Reflected Cross-Site Scripting Vulnerability in Cisco Unified Intelligence Center
CVE-2023-20058
6.1MEDIUM
Summary
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center allows an unauthenticated remote attacker to execute a reflected cross-site scripting (XSS) attack. This issue arises due to improper validation of user-supplied input, enabling attackers to craft malicious links that, when clicked by a user, can lead to the execution of arbitrary script code within the affected interface. Such exploitation can potentially access sensitive browser-based information, posing significant risks to users.
Affected Version(s)
Cisco Packaged Contact Center Enterprise 11.6(1)
Cisco Packaged Contact Center Enterprise 11.6(2)
Cisco Packaged Contact Center Enterprise 12.0(1)
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved