Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
Cisco Unity Express Multiple XSS and CSRF Vulnerabilities
Information
Severity
Severity
Medium
Family
Family
CISCO
CVSSv2 Base
CVSSv2 Base
6.8
CVSSv2 Vector
CVSSv2 Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Solution Type
Solution Type
Vendor Patch
Created
Created
11 years ago
Modified
Modified
5 years ago
Summary
The host is installed with Cisco Unity Express and is prone to multiple cross-site scripting and request forgery vulnerabilities.
Insight
Insight
- Input passed via the 'gui_pagenotableData' parameter to Web/SA2/ScriptList.do and 'holiday.description' parameter to /Web/SA3/AddHoliday.do are not properly sanitized before being returned to the user. - The application allows users to perform certain actions via HTTP requests without performing proper validity checks to verify the requests.
Affected Software
Affected Software
Cisco Unity Express version 7.x
Solution
Solution
Upgrade to Cisco Unity Express 8.0 or later.