cisco-sa-20180718-uccx
Multiple Vulnerabilities in Cisco Unified Contact Center Express
Medium · Updated · Cisco
cisco-sa-20180718-uccx affects 1 Cisco product, including Cisco Unified Contact Center Express and covering 4 CVEs.
4 products with CSAF evidence
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface, conduct a cross-site request forgery (CSRF) attack, or retrieve a cleartext password. For more information about these vulnerabilities, see the Details section of this advisory. There are no workarounds that address these vulnerabilities.
CVSS scores
6.16.1 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:X/RL:X/RC:X6.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:X/RC:X5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:X