Cross-Site Scripting Vulnerability in Cisco Unity Connection Management Interface
CVE-2024-20305
What is CVE-2024-20305?
A vulnerability exists in the web-based management interface of Cisco Unity Connection, allowing authenticated remote attackers to conduct cross-site scripting (XSS) attacks. This vulnerability arises from insufficient validation of user-supplied input. Attackers could exploit this flaw by convincing users to click on specially crafted links, which may enable the execution of arbitrary script code in the context of the affected interface as well as access to sensitive information stored in the user's browser.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Unity Connection 12.0(1)SU1
Cisco Unity Connection 12.0(1)SU2
Cisco Unity Connection 12.0(1)SU3
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved