Cross-Site Scripting Vulnerability in Cisco Jabber Client Framework
CVE-2018-0199

6.1MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
22 February 2018

Summary

A cross-site scripting vulnerability in the Cisco Jabber Client Framework allows unauthenticated remote attackers to execute arbitrary JavaScript within the Jabber client of an affected user. This vulnerability arises from inadequate neutralization of scripts in web page attributes, leading to potential remote code execution. Exploitation of this flaw can enable attackers to manipulate sessions and access sensitive data, posing significant risks to affected devices.

Affected Version(s)

Cisco Jabber Client Framework Cisco Jabber Client Framework

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.