Cross-Site Scripting Vulnerability in Cisco WebEx Meetings Server
CVE-2017-12296

6.1MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
19 October 2017

Summary

A vulnerability exists in Cisco WebEx Meetings Server that allows an unauthenticated remote attacker to perform a cross-site scripting attack. This is attributed to inadequate input validation of certain parameters sent to the server. By enticing a user with a malicious link or intercepting user requests, an attacker could inject malicious scripts. Successful exploitation may lead to arbitrary script execution in the user's web interface and reveal sensitive browser-based information.

Affected Version(s)

Cisco WebEx Meetings Server Cisco WebEx Meetings Server

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.