Stored XSS Vulnerability in Cisco Finesse Web Management Interface
CVE-2024-20405
What is CVE-2024-20405?
A vulnerability in the web-based management interface of Cisco Finesse allows unauthorized, remote attackers to perform stored XSS attacks. This issue arises from insufficient validation of user-supplied input in specific HTTP requests directed to the affected device. Attackers can exploit this vulnerability by convincing users to interact with a malicious link, which could result in executing arbitrary script code in the context of the affected interface. Such an attack might lead to the exposure of sensitive information stored on the device.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Finesse 12.6(2)
Cisco Finesse 12.6(2)ES1
Cisco Finesse 12.6(2)ES2
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published