6.1
CVE-2026-20059
- EPSS 0.04%
- Veröffentlicht 15.04.2026 16:11:22
- Zuletzt bearbeitet 28.04.2026 16:31:07
- Quelle psirt@cisco.com
- CVE-Watchlists
- Unerledigt
Cisco Unity Connection Reflected Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Unity Connection Version <= 12.5
Cisco ≫ Unity Connection Version14.0
Cisco ≫ Unity Connection Version14su1
Cisco ≫ Unity Connection Version14su2
Cisco ≫ Unity Connection Version14su3
Cisco ≫ Unity Connection Version14su3a
Cisco ≫ Unity Connection Version14su4
Cisco ≫ Unity Connection Version14su5
Cisco ≫ Unity Connection Version15.0
Cisco ≫ Unity Connection Version15su1
Cisco ≫ Unity Connection Version15su2
Cisco ≫ Unity Connection Version15su3
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.131 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@cisco.com | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.