Impact
This vulnerability is a stored cross‑site scripting (XSS) flaw in the web‑based management interface of several Cisco Contact Center products. It allows an unauthenticated, remote attacker to inject and execute arbitrary script code within the context of the interface, potentially accessing sensitive browser‑based data. The weakness stems from insufficient input validation (CWE‑79).
Affected Systems
Affected products include Cisco Unified Contact Center Express, Cisco Unified Contact Center Enterprise, Cisco Packaged Contact Center Enterprise, Cisco Finesse, and Cisco Unified Intelligence Center. Specific vulnerable versions are not provided in the data.
Risk and Exploitability
The CVSS v3.1 score is 6.1, indicating moderate severity. EPSS is less than 1%, indicating a low probability of exploitation at current time. The vulnerability is not listed in the CISA KEV catalog. Attackers must first reach the web interface, which is typically exposed through port 8443/443; authentication is not required, so anyone can inject the payload. The impact is limited to the affected user's browser session unless the attacker can move laterally to compromise the underlying system.
OpenCVE Enrichment