Cross-Site Scripting Vulnerability in Cisco Jabber Client Framework
CVE-2018-0201

5.4MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
22 February 2018

Summary

A security flaw in the Cisco Jabber Client Framework has the potential to allow a remote attacker, who is already authenticated, to launch cross-site scripting (XSS) attacks against users of the affected devices. This vulnerability stems from inadequate input handling during the generation of web pages. By crafting specially designed media within instant messages, an attacker can exploit this flaw, which may result in unintended outbound requests being made by the recipient's chat client. This can expose the user to various security risks, including data theft and unauthorized actions.

Affected Version(s)

Cisco Jabber Client Framework Cisco Jabber Client Framework

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.