← Back

CVE-2009-2048

nvd nist
Published: Jul 16, 2009Modified: Apr 23, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to inject arbitrary web script or HTML into the CCX database via unspecified vectors.

Affected (33)

6 products
Crs
Customer Response Applications
Ip Qm
Unified Ccx
Unified Ip Contact Center Express
Unified Ip Ivr
Configuration A
33 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 3.5
Version 4.0
Version 4.1
Version 4.5
Version 5.0
Version 6.0
Version 7.0
Version 3.5
Version 3.5
Cisco
Version 3.5
Version 4.0(1)
Version 4.0(3)
Version 4.0(4)
Version 4.0(5)
Version 4.0(5a)
Version 4.5(1)
Version 4.5(2)
Version 5.0(1)
Version 6.0(1)
Version 7.0(1)
Cisco
Version 3.0
Version 5.0(1)
Version 6.0(1)
Version 7.0
Cisco
Version 3.0
Version 3.1
Version 4.0
Version 4.1
Version 4.5
Version 5.0
Version 6.0
Version 7.0
Version 7.0(1)

References (14)

Source: psirt@cisco.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.