PT-2020-4221 · Cisco · Cisco Webex Meetings
Sai Kiran Battaluri
·
Published
2020-08-05
·
Updated
2021-08-06
·
CVE-2020-3472
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Cisco Webex Meetings (affected versions not specified)
Description:
A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to access sensitive information. The issue is due to improper access restrictions on users who are added within user contacts. An attacker could exploit this by sending specially crafted requests to the Webex Meetings site, potentially allowing them to view the details of users on another Webex site, including user names and email addresses.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Webex Meetings