Mohamed Sayed

Researcher fromIBM X-Force
#7025of 53,634
38.8Total CVSS
Vulnerabilities · 6
Medium
5
High
1
PT-2021-2573
6.4
2021-04-07
Cisco · Cisco Unified Communications Manager Session Management Edition · CVE-2021-1407
**Name of the Vulnerable Software and Affected Versions** Cisco Unified Communications Manager versions (affected versions not specified) Cisco Unified Communications Manager IM & Presence Service versions (affected versions not specified) Cisco Unified Communications Manager Session Management Edition versions (affected versions not specified) Cisco Unity Connection versions (affected versions not specified) **Description** The web-based management interface of the affected Cisco products does not properly validate user-supplied input, allowing an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an interface user. An attacker could exploit this issue by persuading an interface user to click a crafted link, potentially executing arbitrary script code in the context of the affected interface or accessing sensitive browser-based information. **Recommendations** For Cisco Unified Communications Manager, update to a version that properly validates user-supplied input to prevent cross-site scripting attacks. For Cisco Unified Communications Manager IM & Presence Service, update to a version that properly validates user-supplied input to prevent cross-site scripting attacks. For Cisco Unified Communications Manager Session Management Edition, update to a version that properly validates user-supplied input to prevent cross-site scripting attacks. For Cisco Unity Connection, update to a version that properly validates user-supplied input to prevent cross-site scripting attacks. As a temporary workaround, consider restricting access to the web-based management interface to minimize the risk of exploitation.
PT-2021-2574
6.4
2021-04-07
Cisco · Cisco Unified Communications Manager Session Management Edition · CVE-2021-1408
**Name of the Vulnerable Software and Affected Versions** Cisco Unified Communications Manager versions (affected versions not specified) Cisco Unified Communications Manager IM & Presence Service versions (affected versions not specified) Cisco Unified Communications Manager Session Management Edition versions (affected versions not specified) Cisco Unity Connection versions (affected versions not specified) **Description** The web-based management interface of the affected Cisco products does not properly validate user-supplied input, allowing an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an interface user. An attacker could exploit this issue by persuading an interface user to click a crafted link, potentially executing arbitrary script code in the context of the affected interface or accessing sensitive browser-based information. **Recommendations** For Cisco Unified Communications Manager, update to a version that properly validates user-supplied input to prevent XSS attacks. For Cisco Unified Communications Manager IM & Presence Service, update to a version that properly validates user-supplied input to prevent XSS attacks. For Cisco Unified Communications Manager Session Management Edition, update to a version that properly validates user-supplied input to prevent XSS attacks. For Cisco Unity Connection, update to a version that properly validates user-supplied input to prevent XSS attacks. As a temporary workaround, consider restricting access to the web-based management interface to minimize the risk of exploitation.