CVE-2014-2180: Cisco Unified Contact Center Enterprise
Medium severity, CVSS 4.0. EPSS: 0.8% chance of exploitation in the next 30 days.
The Document Management component in Cisco Unified Contact Center Express does not properly validate a parameter, which allows remote authenticated users to upload files to arbitrary pathnames via a crafted HTTP request, aka Bug ID CSCun74133.
Affected products
- Cisco Unified Contact Center Enterprise: any version
- Cisco Unified Contact Center Express Editor Software: affected versions not specified
Published 2014-04-29. Last modified 2026-06-17.