CVE-2024-20405

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability. This vulne

Severity
Medium 4.8
CVSS 3.1
Exploited
Not listed
EPSS
0.006
49.7th percentile
Discovered by
Third party
Vendor-published field
Published
Jun 5, 2024
Assigned by cisco

Description

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability. This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.

Weakness: CWE-20

Affected products

Vendor Product Category Matched by
Cisco Cisco Contact Center Other Products cna-assigner
Vendor-reported products (4)
  • Cisco · Cisco Unified Contact Center Enterprise
  • Cisco · Cisco Unified Contact Center Express
  • Cisco · Cisco Finesse
  • Cisco · Cisco Packaged Contact Center Enterprise

Something wrong here?