Several cross-site scripting vulnerabilities have been identified in Cisco Finesse.
A remote attacker can exploit them in order to execute arbitrary JavaScript or HTML code by enticing their victim into following a specially formed link.
These vulnerabilities are due to a lack of verification of GET or POST requests.
No further information is available.
Cisco announces that a private exploitation code exists.
Vulnerable Products
Vulnerable Software: Finesse (Cisco) - 10.5(1)
Solution
Cisco has released version 10.6(1.10000.39) of Finesse which fixes these vulnerabilities.