CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
AI Score
Confidence
High
EPSS
Percentile
49.1%
Cross-site scripting (XSS) vulnerability in Cisco IM and Presence Service before 10.5 MR1 allows remote attackers to inject arbitrary web script or HTML by constructing a crafted URL that leverages incomplete filtering of HTML elements, aka Bug ID CSCut41766.
Vendor | Product | Version | CPE |
---|---|---|---|
cisco | unified_communications_manager_im_and_presence_service | 9.0(1) | cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:9.0\(1\):*:*:*:*:*:*:* |
cisco | unified_communications_manager_im_and_presence_service | 9.1(1) | cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:9.1\(1\):*:*:*:*:*:*:* |
cisco | unified_communications_manager_im_and_presence_service | 10.5(1) | cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5\(1\):*:*:*:*:*:*:* |