CVE-2020-3346

Severity
6.1MEDIUM
EPSS
0.3%
top 42.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 17
Latest updateMay 24

Description

A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web UI does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A su

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-v5vq-g662-p4fr: A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition2022-05-24
CVEList
Cisco Unified Communications Manager Cross-Site Scripting Vulnerability2020-08-17

📋Vendor Advisories

1
Cisco
Cisco Unified Communications Manager Cross-Site Scripting Vulnerability2020-08-05
CVE-2020-3346 (MEDIUM CVSS 6.1) | A vulnerability in the web UI of Ci | cvebase.io