Cisco Finesse OpenSocial Gadget Editor Cross-Site Scripting Vulnerability
Description
An unauthenticated XSS vulnerability in Cisco Finesse and Unified CVP OpenSocial Gadget Editor allows remote attackers to execute arbitrary script via crafted link.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An unauthenticated XSS vulnerability in Cisco Finesse and Unified CVP OpenSocial Gadget Editor allows remote attackers to execute arbitrary script via crafted link.
Vulnerability
The vulnerability exists in the OpenSocial Gadget Editor component of the web-based management interface of Cisco Finesse and Cisco Unified Customer Voice Portal (CVP). The interface fails to properly validate user-supplied input, allowing injection of malicious script. Affected versions: Cisco Finesse releases earlier than 12.0(1) ES3 and 12.5(1); Cisco Unified CVP releases 12.6(2) ES4 through 12.6(2) ES17. [1]
Exploitation
An unauthenticated, remote attacker can exploit this vulnerability by persuading a user of the interface to click a crafted link. No authentication is required, and the attacker does not need any prior access. The user interaction is required (clicking the link). [1]
Impact
Successful exploitation allows the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information, such as session tokens or cookies. This could lead to further compromise of the system. [1]
Mitigation
Cisco has released software updates to address this vulnerability. For Cisco Finesse, upgrade to Release 12.0(1) ES3 or later, or Release 12.5(1) or later. For Cisco Unified CVP, upgrade to a fixed release beyond 12.6(2) ES17. There are no workarounds. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: 12.6(2)_ES4
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.