CVE-2016-6425

Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuy75020 and CSCuy81652.

Data: Cisco advisories · Cisco CSAF · NVD CVEs · NVD CPEs · CISA KEV · EPSS

SeverityMEDIUM
CVSS6.1
EPSS-
CWECWE-79
KEV
Published
Modified

Products with public affected evidence

Product Advisory Affected evidence
Cisco Unified Contact Center Express cisco-sa-20161005-ucis1 structured affected CSAF product_status
Cisco Unified Intelligence Center cisco-sa-20161005-ucis1 structured affected CSAF product_status