脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Cross-Site Scripting Vulnerability
脆弱性説明
Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. These vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker must have valid administrative credentials.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
脆弱性タイプ
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
脆弱性タイトル
Cisco Packaged Contact Center Enterprise和Cisco Unified Contact Center Enterprise 跨站脚本漏洞
脆弱性説明
Cisco Unified Contact Center Enterprise和Cisco Packaged Contact Center Enterprise都是美国思科(Cisco)公司的产品。Cisco Unified Contact Center Enterprise是一个统一联络中心。Cisco Packaged Contact Center Enterprise是一个客户接触中心系统。 Cisco Packaged Contact Center Enterprise和Cisco Unified
CVSS情報
N/A
脆弱性タイプ
N/A