CVE-2014-2125 | Cisco Unity Connection up to 8.6(2)SU3 Web Inbox cross site scripting (CSCui33028 / XFDB-92230)
A vulnerability labeled as problematic has been found in Cisco Unity Connection up to 8.6(2)SU3. The impacted element is an unknown function of the component Web Inbox. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2014-2125. The attack may be performed from remote. In addition, an exploit is available.
The affected component should be upgraded.