← Back to home
wid-sec-w-2026-0699  ·  Published 2026-03-11  ·  View on BSI CERT-Bund ↗

Cisco Finesse, Unified Intelligence Center, Unified CCX: Multiple Vulnerabilities allow Cross-Site Scripting

CVSS 6.1 MEDIUM

Risk Summary

A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability exists because the web-based management interface of an affected system does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

Affected Vendors

Cisco

Affected Products (6)

Cisco · Finesse <15.0(1)ES202511
Cisco · Finesse 15.0(1)ES202511
Cisco · Unified Contact Center Express (UCCX) <15.0 ES0
Cisco · Unified Contact Center Express (UCCX) 15.0 ES0
Cisco · Unified Intelligence Center <15.0(1)ES202511
Cisco · Unified Intelligence Center 15.0(1)ES202511

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more