漏洞描述 Cisco Unified Communications Manager是美国思科(Cisco)公司的一款统一通信系统中的呼叫处理组件。该组件提供了一种可扩展、可分布和高可用的企业IP电话呼叫处理解决方案。 Cisco Unified Communications Manager存在跨站脚本漏洞,该漏洞源于基于Web的管理界面没有正确验证用户提供的输入。未经身份验证的远程攻击者对该界面的用户发起跨站脚本(XSS)攻击。
相关漏洞推荐 ETAP Safety Manager 跨站脚本漏洞 POC CVE-2020-26836: SAP Solution Manager - Open Redirect POC bitrix-log-file-disclosure: Bitrix Site Manager - Log File Disclosure POC nexus-repository-anonymous-access: Nexus Repository Manager - Anonymous Access Enabled POC CVE-2019-25213: WordPress Advanced Access Manager - Path Traversal POC CVE-2024-20404: Cisco Finesse - Server-Side Request Forgery (SSRF) POC aem-anonymous-write: Adobe Experience Manager (AEM) - Anonymous JCR Node Creation 中成科信票务管理系统 /SystemManager/Api/TicketManager.ashx SQL 注入漏洞 新视窗新一代物业管理系统 /OfficeManagement/RegisterManager/Report/Training/Report/GetprintData.asmx SQL 注入漏洞 Oracle Identity Manager /iam/governance/applicationmanagement/api/v1/applications/groovyscriptstatus;.wadl 命令执行漏洞(CVE-2025-61757) Oracle Identity Manager 访问控制不当漏洞 POC CVE-2025-61757: Oracle Identity Manager REST WebServices - Authentication Bypass 月子会所ERP /Page/SalerManager/ashx/BindRoomListData.ashx RoomType SQL 注入漏洞