Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco Jabber Client Framework Instant Message Cross-Site Scripting Vulnerability

cisco-sa-20190109-jcf-im-xss · Medium · Published · Updated

A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient validation of user-supplied input of an affected client. An attacker could exploit this vulnerability by executing arbitrary JavaScript in the Jabber client of the recipient. A successful exploit could allow the attacker to execute arbitrary script code in the context of the targeted client or allow the attacker to access sensitive client-based information. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190109-jcf-im-xss

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2018-0483
Cisco Bug IDsCSCvm82721
CVSS ScoreBase 4.6
Base 4.6 CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Jabber IM for Android, Cisco Jabber for Windows, Cisco Jabber Guest, Cisco Jabber Video for TelePresence (Movi), Cisco Jabber Software Development Kit, Cisco Jabber for Mac, Cisco Jabber for iOS, Cisco Jabber Client Framework (JCF)

Related Products

Product CVE Evidence
Cisco Jabber for iOS CVE-2018-0483 Cisco OpenVuln
Cisco Jabber for Windows CVE-2018-0483 Cisco OpenVuln
Cisco Jabber for Mac CVE-2018-0483 Cisco OpenVuln
Cisco Jabber Video for TelePresence (Movi) CVE-2018-0483 Cisco OpenVuln
Cisco Jabber Software Development Kit CVE-2018-0483 Cisco OpenVuln
Cisco Jabber IM for Android CVE-2018-0483 Cisco OpenVuln
Cisco Jabber Guest CVE-2018-0483 Cisco OpenVuln
Cisco Jabber Client Framework (JCF) CVE-2018-0483 Cisco OpenVuln
Cisco Jabber CVE-2018-0483 Cisco OpenVuln