Cisco Unified Contact Center Express Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX). This vulnerability allows an unauthenticated, remote attacker to inject malicious scripts that could be executed in the context of the user's browser session, potentially accessing sensitive information.

Impact

Exploitation of this vulnerability allows for cross-site scripting attacks, where an attacker can inject and execute malicious scripts in the context of the user's session.

Remediation

Users are advised to upgrade to Cisco Unified CCX version 15.0 ES02 or later. For versions 12.5 SU3 and earlier, migrating to a fixed release is recommended.

Added: Mar 11, 2026, 5:28 PM
Updated: Mar 11, 2026, 5:28 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
1.7
exploitability
6.0
remediation
7.7
relevance
3.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.