PT-2015-7214 · Datatables+1 · Datatables Plugin+1
Published
2015-12-05
·
Updated
2020-08-31
·
CVE-2015-6384
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco WebEx Meetings versions prior to 8.5.1
DataTables plugin versions 1.10.8 and earlier
Description
The issue allows attackers to bypass intended access restrictions or inject arbitrary web script or HTML. For the DataTables plugin, this can be done via the
scripts parameter to the "media/unit testing/templates/6776.php" endpoint.Recommendations
For Cisco WebEx Meetings versions prior to 8.5.1, update to version 8.5.1 or later.
For DataTables plugin versions 1.10.8 and earlier, update to a version greater than 1.10.8, such as version 1.10.10.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Webex Meetings
Datatables Plugin