Executive brief
Cisco Finesse, a customer service collaboration platform, contains a vulnerability that allows an attacker to inject malicious content into a user's active session. By tricking a user into clicking a specially crafted link, an attacker can execute unauthorized scripts in the user's browser or access sensitive information. This could lead to unauthorized actions being performed on behalf of the user or the theft of session data.
Technical details
A Remote File Inclusion (RFI) vulnerability exists in Cisco Finesse due to insufficient validation of user-supplied input in HTTP requests. An unauthenticated remote attacker can exploit this by persuading a user to click a crafted URL containing the address of the affected device. Successful exploitation allows the attacker to load arbitrary files from remote locations into the user's session, enabling the execution of malicious scripts (XSS) or the retrieval of sensitive information within the context of the affected interface. Cisco has released software updates in version 15.0(1)SU1 to address this issue; no workarounds are available.
Affected products
- Cisco Finesse Earlier than 15.0(1)SU1
Timeline
- 2026-06-03: disclosed: Initial public release of Cisco advisory
- 2026-06-03: patched: Fixed in Cisco Finesse 15.0(1)SU1