Cisco Unified Contact Center Express Cross-Site Scripting Vulnerability
Description
(:A vulnerability has been identified in the HTTP web-based management interface of Cisco Unified Contact Center Express.:A remote attacker could exploit it by inciting their victim into following a specially formed link in order to execute arbitrary Javascript or HTML code.::The vulnerability is due to insufficient input validation of a user-supplied value.::This vulnerability applies to all Permanent Web Links (permalinks) accessible from the web interface.)