4.3
CVSSv2

CVE-2015-4206

Published: 15/12/2015 Updated: 07/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cisco Unified Communications Manager (UCM) 8.0 up to and including 8.6 allows remote malicious users to bypass an XSS protection mechanism via a crafted parameter, aka Bug ID CSCuu15266.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager 8.0\\(2c\\)

cisco unified communications manager 8.0\\(3\\)

cisco unified communications manager 8.0_base

cisco unified communications manager 8.6.2

cisco unified communications manager 8.6_base

cisco unified communications manager 8.5_base

cisco unified communications manager 8.5.1

cisco unified communications manager 8.6.1

Vendor Advisories

A cross-site scripting (XSS) filter bypass vulnerability in the web management interface of Cisco Unified Communications Manager (UCM) versions 80 through 86 could allow an unauthenticated, remote attacker to mount XSS attacks against a user of an affected device The vulnerability is due to a failure to properly call XSS filter subsystems when ...