PT-2015-7214 · Datatables+1 · Datatables Plugin+1
Publicado
2015-12-05
·
Atualizado
2020-08-31
·
CVE-2015-6384
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco WebEx Meetings versions prior to 8.5.1
DataTables plugin versions 1.10.8 and earlier
Description
The issue allows attackers to bypass intended access restrictions or inject arbitrary web script or HTML. For the DataTables plugin, this can be done via the
scripts parameter to the "media/unit testing/templates/6776.php" endpoint.Recommendations
For Cisco WebEx Meetings versions prior to 8.5.1, update to version 8.5.1 or later.
For DataTables plugin versions 1.10.8 and earlier, update to a version greater than 1.10.8, such as version 1.10.10.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cisco Webex Meetings
Datatables Plugin