VYPR
Unrated severityNVD Advisory· Published Jan 13, 2021· Updated Sep 16, 2024

Cisco Finesse OpenSocial Gadget Editor Cross-Site Scripting Vulnerability

CVE-2021-1245

Description

An unauthenticated XSS vulnerability in Cisco Finesse and Unified CVP OpenSocial Gadget Editor allows remote attackers to execute arbitrary script via crafted link.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated XSS vulnerability in Cisco Finesse and Unified CVP OpenSocial Gadget Editor allows remote attackers to execute arbitrary script via crafted link.

Vulnerability

The vulnerability exists in the OpenSocial Gadget Editor component of the web-based management interface of Cisco Finesse and Cisco Unified Customer Voice Portal (CVP). The interface fails to properly validate user-supplied input, allowing injection of malicious script. Affected versions: Cisco Finesse releases earlier than 12.0(1) ES3 and 12.5(1); Cisco Unified CVP releases 12.6(2) ES4 through 12.6(2) ES17. [1]

Exploitation

An unauthenticated, remote attacker can exploit this vulnerability by persuading a user of the interface to click a crafted link. No authentication is required, and the attacker does not need any prior access. The user interaction is required (clicking the link). [1]

Impact

Successful exploitation allows the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information, such as session tokens or cookies. This could lead to further compromise of the system. [1]

Mitigation

Cisco has released software updates to address this vulnerability. For Cisco Finesse, upgrade to Release 12.0(1) ES3 or later, or Release 12.5(1) or later. For Cisco Unified CVP, upgrade to a fixed release beyond 12.6(2) ES17. There are no workarounds. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.