PT-2019-1393 · Cisco · Cisco Webex Business Suite
Published
2019-02-06
·
Updated
2023-03-24
·
CVE-2019-1680
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Webex Business Suite versions prior to 3.0.9
Description
A vulnerability in Cisco Webex Business Suite exists due to improper validation of input, allowing an unauthenticated, remote attacker to inject arbitrary text into a user's browser. This can be exploited by convincing a targeted user to view a malicious URL, potentially leading to spoofing attacks.
Recommendations
For versions prior to 3.0.9, update to version 3.0.9 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially malicious URLs to minimize the risk of exploitation.
Fix
Special Elements Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Webex Business Suite