Cisco Bug: CSCum95568 - UCCX OS admin webapp vulnerable to XSS set through login message upload
Aug 06, 2018
- Cisco Unified Contact Center Express
- Cisco Unified IP Interactive Voice Response (IVR) 10.5(1)
- Cisco Unified Contact Center Express 10.5(1)
Known Affected Releases
Symptoms: Cisco Unified Contact Center Express (UCCX) is vulnerable to a Cross-Site Scripting (XSS) vulnerability in the OS Administration page. Conditions: A default installation of an affected version of UCCX.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases