Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-58261
HistoryJul 22, 2021 - 12:00 a.m.

Cisco Unified Customer Voice Portal Cross-Site Scripting Vulnerability

2021-07-2200:00:00
China National Vulnerability Database
www.cnvd.org.cn
14
cisco
cvp
xss
vulnerability
web management
exploit
attack
arbitrary code

EPSS

0.001

Percentile

28.6%

Cisco Unified Customer Voice Portal (CVP) can be used as a standalone interactive voice response (IVR) system or integrated with a contact center.A cross-site scripting vulnerability exists in the Web management interface of Cisco Unified Customer Voice Portal 12.5(1) and prior versions, which could be exploited by an attacker to Exploit the vulnerability by tricking users into clicking on a malicious link to execute arbitrary code in the context of the interface, access sensitive, browser-based information, or under certain conditions, cause the affected device to reboot.

EPSS

0.001

Percentile

28.6%

Related for CNVD-2021-58261