Cisco Unified Presence Server Cross-Site Scripting Vulnerability (CVE-2015-4220)
Cisco Unified Presence Server Cross-Site Scripting Vulnerability (CVE-2015-4220)
Release date:
Updated on:
Affected Systems:
Cisco Unified Presence Server 9.1 (1)
Description:
CVE (CAN) ID: CVE-2015-4220
Cisco Unified Presence is an enterprise-level platform driven by Jabber XMPP. It can collect information about user availability and communication functions to provide Unified user network status, provides support for Cisco Unified Communications and key business applications based on network status.
A cross-site scripting vulnerability exists in Cisco uniied Presence Server 9.1 (1). Remote attackers can exploit this vulnerability to inject arbitrary Web scripts or HTML.
<* Source: Cisco
*>
Suggestion:
Vendor patch:
Cisco
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://tools.cisco.com/security/center/viewAlert.x? AlertId = 39504
This article permanently updates the link address: