CVE Database
/

CVE-2017-12258

Back to search

CVE-2017-12258

Published: Oct 5, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

A vulnerability in the web-based UI of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack. The vulnerability exists because the affected software does not provide sufficient protections for HTML inline frames (iframes). An attacker could exploit this vulnerability by directing a user of the affected software to an attacker-controlled web page that contains a malicious HTML inline frame. A successful exploit could allow the attacker to conduct click-jacking or other types of client-side browser attacks. Cisco Bug IDs: CSCve60993.

VendorProductVersions

n/a

Cisco Unified Communications Manager

affected
Cisco Unified Communications Manager

Weaknesses (CWE)

References

101172
vdb-entry
x_refsource_BID
1039505
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now