CVE-2015-0749
published 2020-02-19CVE-2015-0749: A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on the…
PriorityP429medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.79%
52.4th percentile
A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on the affected software. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker could exploit this vulnerability by convincing a user to follow a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected site or allow the attacker to access sensitive browser-based information.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_communications_manager | >= next of 11.5(0.98000.108) < unspecified | unspecified |
| cisco | unified_communications_manager | <= 10.5\(2.10000.5\) | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q5h4-crfg-8c2v: A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack
ghsa_unreviewed·2022-05-24
CVE-2015-0749 [MEDIUM] GHSA-q5h4-crfg-8c2v: A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack
A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on the affected software. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker could exploit this vulnerability by convincing a user to follow a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected site or allow the attacker to access sensitive browser-based information.
Cisco
Cisco Unified Communications Manager Multiple Vulnerabilities
vendor_cisco·2015-05-22·CVSS 4.3
CVE-2015-0749 [MEDIUM] CWE-20 Cisco Unified Communications Manager Multiple Vulnerabilities
Cisco Unified Communications Manager Multiple Vulnerabilities
Multiple vulnerabilities in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS), cross-site request forgery (XSRF), and phishing attacks on the affected software.
The vulnerabilities are due to improper input validation of certain parameters passed to the affected software. An attacker could exploit these vulnerabilities by convincing a user to follow a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected site or allow the attacker to access sensitive browser-based information.
Cisco has confirmed these vulnerabilities and software updates are available.
To exploit these vulnerabili
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-02-19
Published