CVE-2023-20265P4MEDIUMCVSS 5.4fixed in 5.1.2sr12023-11-21
CVE-2023-20265 [MEDIUM] CWE-79 CVE-2023-20265: A vulnerability in the web-based management interface of a small subset of Cisco IP Phones could all
A vulnerability in the web-based management interface of a small subset of Cisco IP Phones could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit thi
nvd