CVE-2023-20242
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
EPSS 0.15% · 35.9th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Unified Communications Manager IM and Presence Service | N/A |
| Cisco | Cisco Unified Communications Manager / Cisco Unity Connection | *, 10.5(2)SU6a, 11.0(1) |
| cisco | unified_communications_manager_im_and_presence_service | 14.0, 12.5\(1\), 11.5\(1\) |
| Cisco | Cisco Unified Communications Manager | 12.0(1)SU1, 12.0(1)SU4, 12.0(1)SU5 |
| cisco | unified_communications_manager | 11.5\(1\), 12.5\(1\), 12.5\(1\) |
Exploit Intelligence
- cisco-sa-cucm-imp-xss-QtT4VdsK (circl)
Timeline
- Aug 16, 2023 CVE Published
- Aug 18, 2023 EPSS Score
- Sep 20, 2023 EPSS Score
- Oct 24, 2023 EPSS Score
- Nov 26, 2023 EPSS Score
- Dec 29, 2023 EPSS Score
- Feb 1, 2024 EPSS Score
- Mar 5, 2024 EPSS Score
- Apr 7, 2024 EPSS Score
- May 10, 2024 EPSS Score
- Jun 13, 2024 EPSS Score
- Jul 16, 2024 EPSS Score