CVE-2024-20488 is a medium-severity cross-site scripting (XSS) vulnerability affecting the web-based management interface of Cisco Unified Communications Manager and Unified CM SME. An unauthenticated, remote attacker could exploit this by tricking a user into clicking a crafted link, leading to arbitrary script execution or access to sensitive browser information. The attack complexity is low, but user interaction is required. There is currently no public exploit code, evidence of active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.5\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:12.5\(1\):*:*:*:*:*:*:* | ||
12.5\(1\)su1CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:12.5\(1\)su1:*:*:*:*:*:*:* | ||
12.5\(1\)su2CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:12.5\(1\)su2:*:*:*:*:*:*:* | ||
12.5\(1\)su3CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:12.5\(1\)su3:*:*:*:*:*:*:* | ||
12.5\(1\)su4CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:12.5\(1\)su4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.