Impact
A cross‑site scripting flaw exists in the Desktop Agent component of Cisco Webex Contact Center. The attacker can embed malicious HTML or script that, when a user follows a crafted link, executes in the victim’s browser. The impact is the theft of sensitive information stored in the browser, including authentication tokens and session data, which can lead to unauthorized access to the Webex environment.
Affected Systems
The vulnerability affects the Cisco Webex Contact Center product line, specifically the Desktop Agent functionality. No specific version range is provided, so any installation of the Desktop Agent that has not yet incorporated the vendor’s fix may be impacted.
Risk and Exploitability
The CVSS base score is 6.1, indicating moderate severity. No EPSS score is available and the issue is not listed in CISA’s KEV catalog. Exploitation requires an unauthenticated remote attacker to persuade a user to click a malicious link, meaning it is contingent on user interaction. The risk remains moderate, but as the vendor has issued an internal fix and no customer action is required, the immediate likelihood of exploitation is reduced if the product is current.
OpenCVE Enrichment