PT-2020-4893 · Cisco · Cisco Webex Meetings

Published

2020-11-18

·

Updated

2020-11-25

·

CVE-2020-27126

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Webex Meetings (affected versions not specified)
Description: The issue is related to improper validation of user-supplied input to an application programmatic interface (API) within Cisco Webex Meetings, allowing an unauthenticated, remote attacker to conduct cross-site scripting attacks. An attacker could exploit this by convincing a targeted user to follow a link designed to submit malicious input to the API used by Cisco Webex Meetings. A successful exploit could allow the attacker to conduct cross-site scripting attacks and potentially gain access to sensitive browser-based information from the system of a targeted user.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05468
CVE-2020-27126

Affected Products

Cisco Webex Meetings