PT-2021-1762 · Cisco · Cisco Webex Teams
Hou Jingyi
·
Published
2021-01-13
·
Updated
2021-01-20
·
CVE-2021-1242
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Cisco Webex Teams (affected versions not specified)
Description:
A vulnerability in Cisco Webex Teams could allow an unauthenticated, remote attacker to manipulate file names within the messaging interface. The issue exists due to the software's mishandling of character rendering. An attacker could exploit this by sharing a file within the application interface, potentially allowing them to modify how the shared file name displays. This could enable the attacker to conduct phishing or spoofing attacks.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Webex Teams