Cisco Unified MeetingPlace Microsoft Outlook Reflected Cross-Site Scripting Vulnerability

Related Vulnerabilities: CVE-2015-0762  

A vulnerability in the HTTP web-based management interface of the Cisco Unified MeetingPlace for Microsoft Outlook could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web interface of the affected system. The XSS attack can be executed from the client browser or within Microsoft Outlook. The vulnerability is due to insufficient input validation of a user-supplied value. An attacker could exploit this vulnerability by convincing a user to click on a specific link. A successful exploit could allow the attacker to execute arbitrary script in the context of the affected site or allow the attacker to access sensitive browser-based information. Cisco has confirmed the vulnerability; however, software updates are not available. To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and uses misleading language or instructions to persuade the user to follow the link. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.