Vulnslist

find the latest Cisco vulnerabilities

Cisco IM and Presence Service Reflected Cross-Site Scripting Vulnerability

Cisco-SA-20150730-CVE-2015-4294 · Medium · Published · Updated

Cisco IM and Presence Service contains a reflected cross-site scripting (XSS) vulnerability that could allow an unauthenticated, remote attacker to preform an XSS attack on an authenticated user. The vulnerability is due to an incomplete user input filter that may not filter certain HTML or script tags. An attacker who can convince an authenticated administrator to follow a malicious link or visit an attacker-controlled website could cause arbitrary HTML or script content to be executed in the security context of the affected site on the user's browser. Cisco has confirmed the vulnerability and released software updates. To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the provided link. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Workarounds

Administrators are advised to apply the appropriate updates.

Users should verify that unsolicited links are safe to follow.

For additional information about XSS attacks and the methods used to exploit these vulnerabilities, see the Cisco Applied Mitigation Bulletin Understanding Cross-Site Scripting (XSS) Threat Vectorshttp://www.cisco.com/c/en/us/support/docs/cmb/cisco-amb-20060922-understanding-xss.html .

Administrators are advised to monitor affected systems.

CVEsCVE-2015-4294
Cisco Bug IDsCSCut41766
CVSS ScoreBase 4.3
Base 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N/E:F/RL:OF/RC:C
Product Names From Source
Cisco Unified Communications Manager IM and Presence Service

Related Products

Product CVE Evidence
Cisco Unified Communications Manager CVE-2015-4294 Cisco OpenVuln
Cisco Unified Communications Manager IM and Presence Service CVE-2015-4294 Cisco OpenVuln