Total vulnerabilities in the database
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability.
This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.
Software | From | Fixed in |
---|---|---|
cisco / finesse | 11.6(1) | 11.6(1).x |
cisco / finesse | 12.6(2)-es01 | 12.6(2)-es01.x |
cisco / finesse | 12.6(2)-es02 | 12.6(2)-es02.x |
cisco / finesse | 12.6(2) | 12.6(2).x |
cisco / finesse | - | 11.6\(1\) |
cisco / finesse | 11.6(1)-es4 | 11.6(1)-es4.x |
cisco / finesse | 11.6(1)-es5 | 11.6(1)-es5.x |
cisco / finesse | 11.6(1)-es6 | 11.6(1)-es6.x |
cisco / finesse | 11.6(1)-es7 | 11.6(1)-es7.x |
cisco / finesse | 11.6(1)-es8 | 11.6(1)-es8.x |