Description
Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. These vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker must have valid administrative credentials.
CVSS breakdown
Affected products
- Cisco / Cisco Packaged Contact Center Enterprise12.5(1) – 12.5(1)
- Cisco / Cisco Packaged Contact Center Enterprise11.0(1) – 11.0(1)
- Cisco / Cisco Packaged Contact Center Enterprise12.0(1) – 12.0(1)
- Cisco / Cisco Packaged Contact Center Enterprise11.0(2) – 11.0(2)
- Cisco / Cisco Packaged Contact Center Enterprise11.5(1) – 11.5(1)
- Cisco / Cisco Packaged Contact Center Enterprise10.5(1) – 10.5(1)
- Cisco / Cisco Packaged Contact Center Enterprise10.5(2) – 10.5(2)
- Cisco / Cisco Packaged Contact Center Enterprise11.6(2) – 11.6(2)
- Cisco / Cisco Packaged Contact Center Enterprise10.5(1)_ES7 – 10.5(1)_ES7
- Cisco / Cisco Packaged Contact Center Enterprise11.6(1) – 11.6(1)
- Cisco / Cisco Packaged Contact Center Enterprise10.5(2)_ES8 – 10.5(2)_ES8
- Cisco / Cisco Packaged Contact Center Enterprise12.6(1) – 12.6(1)
- Cisco / Cisco Packaged Contact Center Enterprise12.5(2) – 12.5(2)
- Cisco / Cisco Packaged Contact Center Enterprise12.6(2) – 12.6(2)
- Cisco / Cisco Packaged Contact Center Enterprise15.0(1) – 15.0(1)
- Cisco / Cisco Unified Contact Center Enterprise12.6(1)ES3 – 12.6(1)ES3
- Cisco / Cisco Unified Contact Center Enterprise12.6(1)ES1 – 12.6(1)ES1
- Cisco / Cisco Unified Contact Center Enterprise12.6(1) – 12.6(1)
- Cisco / Cisco Unified Contact Center Enterprise12.6(1)ES2 – 12.6(1)ES2
- Cisco / Cisco Unified Contact Center Enterprise12.6(1)SecurityPatch – 12.6(1)SecurityPatch
- Cisco / Cisco Unified Contact Center Enterprise12.5(1)ES1 – 12.5(1)ES1
- Cisco / Cisco Unified Contact Center Enterprise12.5(1) – 12.5(1)
- Cisco / Cisco Unified Contact Center Enterprise12.6(1)ES4 – 12.6(1)ES4
- Cisco / Cisco Unified Contact Center Enterprise11.0(1) – 11.0(1)
- Cisco / Cisco Unified Contact Center Enterprise10.5(1) – 10.5(1)
- Cisco / Cisco Unified Contact Center Enterprise12.0(1) – 12.0(1)
- Cisco / Cisco Unified Contact Center Enterprise10.5 – 10.5
- Cisco / Cisco Unified Contact Center Enterprise11.0 – 11.0
- Cisco / Cisco Unified Contact Center Enterprise11.5 – 11.5
- Cisco / Cisco Unified Contact Center Enterprise12.6(2) – 12.6(2)
- Cisco / Cisco Unified Contact Center Enterprise12.6(2)ES1 – 12.6(2)ES1
- Cisco / Cisco Unified Contact Center Enterprise12.6(2)ES2 – 12.6(2)ES2
- Cisco / Cisco Unified Contact Center Enterprise15.0(1) – 15.0(1)
- Cisco / Cisco Unified Contact Center Enterprise12.6(2)ES3 – 12.6(2)ES3
- Cisco / Cisco Unified Contact Center Enterprise15.0(1)ET01 – 15.0(1)ET01
- Cisco / Cisco Unified Contact Center Enterprise15.0(1)_SP1 – 15.0(1)_SP1
- Cisco / Cisco Unified Contact Center Enterprise15.0(1)ES202508 – 15.0(1)ES202508