Cross-site Scripting Vulnerability in Cisco Unity Connection
CVE-2016-1310

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
6 February 2016

Summary

The vulnerability in Cisco Unity Connection allows remote attackers to exploit an XSS flaw, enabling them to inject arbitrary web scripts or HTML through specially crafted URLs. This can compromise user sessions or manipulate the way pages are displayed to users. Organizations using affected versions of Cisco Unity Connection should take precautionary measures to secure their web applications and mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.