Tuesday, January 8, 2019

CP-79xx series vulnerable to XSS (10/2018)


Details

cisco-cve201815434-xss (150750)   reported Oct 3, 2018

Cisco Unified IP Phone 7900 Series is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the web-based management interface. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

Workaround:
Disable web-management interface access in CUCM and activate only when needed.

No comments:

Post a Comment

Thank you for your comment. Will try to react as soon as possible.

Regards,

Networ King