cisco-sa-20151120-tvcs
Cisco TelePresence Video Communication Server Cross-Site Request Forgery Vulnerability
Medium · Updated · Cisco
1 product with CSAF evidence
A vulnerability in Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to execute unwanted actions. The vulnerability is due to a lack of cross-site request forgery (CSRF) protections. An attacker could exploit this vulnerability by persuading a user of the web application to execute an adverse action. Cisco has not released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.