CVE-2024-20540 - CVE House
Back to Database
Status published Medium CVE-2024-20540

Cisco Unified Contact Center Management Portal Stored Cross-Site Scripting Vulnerability

Vulnerability Description

A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) could allow an authenticated, remote attacker with low privileges to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into a specific page of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information. To exploit this vulnerability, the attacker must have at least a Supervisor role on an affected device.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-20540

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco Unified Contact Center Management Portal
Vulnerable Versions:
12.5(1)_ES1, 11.6(1)_ES11, 12.5(1)_ES3, 11.6(1)ES2, 10.5(1)ES7, 11.6(1)_ES17, 11.5(1)ES6, 12.5(1), 11.6(1)ES1, 12.0(1)_ES4, 10.5(1)ES1, 11.5(1)ES1, 12.5(1)_ES5, 12.0(1)_ES3, 11.5(1)ES5, 11.6(1)_ES7, 12.0(1)_ES1, 11.5(1)ES8, 11.6(1)_ES9, 10.5(1)ES12, 11.0(1)ES1, 11.6(1)_ES16, 11.5(1)ES7, 11.5(1)ES3, 11.6(1)_ES3, 10.5(1)ES11, 10.5(1)ES10, 11.5(1)ES4, 10.5(1)ES3, 12.6(1), 12.6(1)_ES1, 11.6(1), 12.0(1)_ES2, 11.6(1)_ES13, 12.5(1)_ES2, 10.5(1)ES2, 10.5(1)ES13, 11.6(1)_ES12, 11.0(1)ES3, 11.6(1)_ES5, 11.5(1)ES9, 10.5(1)ES4, 12.6(1)_ES2, 12.0(1), 10.5(1)ES6, 11.6(1)_ES4, 11.6(1)_ES14, 11.0(1)ES2, 12.0(1)_ES5, 10.5(1)ES5, 12.5(1)_ES4, 11.6(1)_ES15, 10.5(1)ES8, 11.6(1)_ES6, 10.5(1)ES9, 11.6(1)_ES10, 11.5(1)ES2, 11.0(1), 12.5(1)_ES6, 12.6(1)_ES3, 12.6(1)_ES4, 12.5(1)_ES7, 12.6(1)_ES5, 12.6(1)_ES6, 12.5(1)_ES8, 12.5(1)_ES9, 12.6(1)_ES7, 12.6(1)_ES8, 12.5(1)_ES10, 10.5(1), 11.5(1), 12.6(1)_ES9, 12.6(1)_ES10, 12.5(1)_ES11, 12.6(1)_ES11, 12.6(1)_ES12, 12.5(1)_ES12, 12.6(1)_ES13

Timeline

Official Publish: November 6th, 2024
Last Modified: November 6th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)