Cross-site Scripting Vulnerability in Cisco Unity Connection
CVE-2016-1310
6.1MEDIUM
Summary
The vulnerability in Cisco Unity Connection allows remote attackers to exploit an XSS flaw, enabling them to inject arbitrary web scripts or HTML through specially crafted URLs. This can compromise user sessions or manipulate the way pages are displayed to users. Organizations using affected versions of Cisco Unity Connection should take precautionary measures to secure their web applications and mitigate the risks associated with this vulnerability.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved