CVE-2018-0199

MEDIUM

Cisco Jabber - Unauthenticated Stored Cross-Site Scripting via Script in Web Page Attributes

Title source: llm
STIX 2.1

Description

A vulnerability in Cisco Jabber Client Framework (JCF) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to improper neutralization of script in attributes in a web page. An attacker could exploit this vulnerability by executing arbitrary JavaScript in the Jabber client of the recipient. An exploit could allow the attacker to perform remote code execution. Cisco Bug IDs: CSCve53989.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040407
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103143

Scores

CVSS v3 6.1
EPSS 0.0207
EPSS Percentile 79.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (3)
cisco/jabber 11.9
cisco/jabber 11.9\(0\)
cisco/jabber
Published Feb 22, 2018
Tracked Since Feb 18, 2026