cisco-sa-20160328-ucdm

Cisco Unified Communications Domain Manager Cross-Site Scripting Vulnerability

Medium · Updated · Cisco

1 product with CSAF evidence

A vulnerability in the Cisco Unified Communications Domain Manager (Unified CDM) could allow an authenticated, remote attacker to execute a cross-site scripting (XSS) attack. The vulnerability is due to insufficient input validation of user-supplied input. An attacker could exploit this vulnerability by convincing a user to access a malicious link. An exploit could allow the attacker to execute arbitrary script code in the context of the affected site. Workarounds that address this vulnerability are not available.