PT-2021-2571 · Cisco · Cisco Unified Intelligence Center+1

Tarkan

·

Published

2021-04-07

·

Updated

2021-04-13

·

CVE-2021-1463

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Unified Intelligence Center (affected versions not specified) Cisco Unified Contact Center Express (affected versions not specified)
Description: The issue is related to the web-based management interface of the affected software, where insufficient protection of the web page structure allows for exploitation. This could enable a remote attacker to perform cross-site scripting (XSS) attacks. The vulnerability exists due to improper validation of user-supplied input. An attacker could exploit this by persuading a user to click on a crafted link, potentially allowing the execution of arbitrary script code or access to sensitive browser-based information.
Recommendations: For Cisco Unified Intelligence Center, update to a version that properly validates user-supplied input to prevent XSS attacks. For Cisco Unified Contact Center Express, ensure that the web-based management interface is configured to validate user input correctly to mitigate the risk of XSS attacks. As a temporary workaround, consider restricting access to the web-based management interface until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02022
CVE-2021-1463

Affected Products

Cisco Unified Contact Center Express
Cisco Unified Intelligence Center