cisco unity-connection CVE-2020-3129 is a vulnerability in Cisco Unity Connection
Published on January 26, 2020

Cisco Unity Connection Stored Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Unity Connection Software could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by providing crafted data to a specific field within the interface. A successful exploit could allow the attacker to store an XSS attack within the interface. This stored XSS attack would then be executed on the system of any user viewing the attacker-supplied data element.

Vendor Advisory NVD

Weakness Type

What is a XSS Vulnerability?

The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE-2020-3129 has been classified to as a XSS vulnerability or weakness.


Products Associated with CVE-2020-3129

Want to know whenever a new CVE is published for Cisco Unity Connection? stack.watch will email you.

 

Affected Versions

Cisco Unity Connection:

Exploit Probability

EPSS
0.26%
Percentile
48.99%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.