High
CVE-2023-20010
Cisco Unified Communications Manager is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL statements to the system, which could allow the attacker to read or modify any data on the underlying database or elevate their privileges.
Cisco
Refer to Cisco Security Advisory for patch, upgrade or suggested workaround information.