URL Redirection Vulnerability in Cisco Webex Meetings
CVE-2025-20291
4.3MEDIUM
What is CVE-2025-20291?
A vulnerability in Cisco Webex Meetings enables an unauthenticated, remote attacker to exploit insufficient URL validation in meeting-join links. By crafting a malicious join URL, the attacker could redirect a targeted user to a potentially harmful website, which might mislead the user into thinking it is a legitimate Webex page. This exploit heightens the risk of phishing attacks, as users may inadvertently provide sensitive information on the fraudulent site. Cisco has implemented measures to mitigate this risk, eliminating the need for customer action.
Affected Version(s)
Cisco Webex Meetings