Cross-Site Scripting Vulnerability in Cisco Jabber Client Framework
CVE-2018-0201
5.4MEDIUM
Summary
A security flaw in the Cisco Jabber Client Framework has the potential to allow a remote attacker, who is already authenticated, to launch cross-site scripting (XSS) attacks against users of the affected devices. This vulnerability stems from inadequate input handling during the generation of web pages. By crafting specially designed media within instant messages, an attacker can exploit this flaw, which may result in unintended outbound requests being made by the recipient's chat client. This can expose the user to various security risks, including data theft and unauthorized actions.
Affected Version(s)
Cisco Jabber Client Framework Cisco Jabber Client Framework
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved