Cross-Site Scripting Vulnerability in Cisco WebEx Meetings Server
CVE-2017-12296
6.1MEDIUM
Summary
A vulnerability exists in Cisco WebEx Meetings Server that allows an unauthenticated remote attacker to perform a cross-site scripting attack. This is attributed to inadequate input validation of certain parameters sent to the server. By enticing a user with a malicious link or intercepting user requests, an attacker could inject malicious scripts. Successful exploitation may lead to arbitrary script execution in the user's web interface and reveal sensitive browser-based information.
Affected Version(s)
Cisco WebEx Meetings Server Cisco WebEx Meetings Server
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved