Skip to content

CVE-2014-2125

Cross-site scripting (XSS) vulnerability in the Web Inbox in Cisco Unity Connection 8.6(2a)SU3 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCui33028.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0032 (0.3%)
Percentile: 55.2%
EPSS: 2026-05-06

Affects

cisco:unity_connection

Technical description

Cross-site scripting (XSS) vulnerability in the Web Inbox in Cisco Unity Connection 8.6(2a)SU3 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCui33028.

Published: 4/2/2014, 3:58:17 AM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam