XSS Vulnerability in Cisco Unified Contact Center Express Management Interface
CVE-2017-12288
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 19 October 2017
What is CVE-2017-12288?
A security flaw exists in the web-based management interface of Cisco Unified Contact Center Express that allows an unauthenticated remote attacker to perform cross-site scripting (XSS) attacks. This vulnerability stems from inadequate validation of user-supplied input. By convincing a user to click on a specially crafted link, an attacker could execute arbitrary script code within the context of the interface, potentially accessing sensitive browser-based information. This flaw is documented in Cisco Bug IDs: CSCvf09173.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Unified Contact Center Express Cisco Unified Contact Center Express
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved