Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco Packaged Contact Center Enterprise Cross-Site Scripting Vulnerability
Vulnerability Description
A vulnerability in the web-based management interface of Cisco Packaged Contact Center Enterprise could allow an unauthenticated, remote attacker to conduct a stored XSS attack against a user of the interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a customized link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive browser-based information.
CVSS Information
N/A
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
Cisco Packaged Contact Center Enterprise 跨站脚本漏洞
Vulnerability Description
Cisco Packaged Contact Center Enterprise是美国思科(Cisco)公司的全渠道客户关怀解决方案。该产品主要提供自助式交互语音应答(IVR)和多通道自动呼叫分配。 Cisco Packaged Contact Center Enterprise中的基于Web的管理界面存在跨站脚本漏洞,该漏洞源于该界面对用户提交的输入验证不充分。远程攻击者可通过诱使用户点击特制的链接利用该漏洞在界面的上下文中执行任意脚本代码或获取基于浏览器的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A