A vulnerability in the web-based interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an authenticated user of the interface.
 This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 01 Aug 2025 19:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.0\(1\):*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.0\(1\)su1:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.0\(1\)su2:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5\(1\):*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5\(1\)su1:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5\(1\)su2:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5\(1\)su3:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5\(2\):*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5\(2\)su1:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5\(2\)su2:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5\(2\)su2a:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5\(2\)su3:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5\(2\)su4:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5\(2\)su4a:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5\(2a\):*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5\(2b\):*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.0\(1\):*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.0\(1\)su1:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\):*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\)su10:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\)su11:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\)su1:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\)su2:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\)su3:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\)su3a:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\)su4:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\)su5:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\)su5a:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\)su6:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\)su7:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\)su8:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\)su9:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.5\(1\):*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.5\(1\)su1:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.5\(1\)su2:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.5\(1\)su3:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.5\(1\)su4:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.5\(1\)su5:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.5\(1\)su6:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.5\(1\)su7:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:14.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:14.0su1:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:14.0su2:*:*:*:*:*:*:* cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:14.0su2a:*:*:*:*:*:*:* | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: cisco
Published: 2024-04-03T16:19:40.031Z
Updated: 2024-08-01T21:59:41.851Z
Reserved: 2023-11-08T15:08:07.631Z
Link: CVE-2024-20310
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-01T21:59:41.851Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-04-03T17:15:48.513
Modified: 2025-08-01T18:52:58.220
Link: CVE-2024-20310
 Redhat
                        Redhat
                    No data.