Tuesday, January 8, 2019
CP-79xx series vulnerable to XSS (10/2018)
Details
cisco-cve201815434-xss (150750) reported Oct 3, 2018
Cisco Unified IP Phone 7900 Series is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the web-based management interface. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
Workaround:
Disable web-management interface access in CUCM and activate only when needed.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment
Thank you for your comment. Will try to react as soon as possible.
Regards,
Networ King