PT-2022-3985 · Cisco · Cisco Webex Meetings

Published

2022-08-03

·

Updated

2023-06-27

·

CVE-2022-20852

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Webex Meetings (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the web interface of Cisco Webex Meetings, which could allow a remote attacker to conduct a cross-site scripting (XSS) attack or a frame hijacking attack against a user of the web interface. The vulnerability is also associated with incorrect restriction of visualizable layers or frames of the user interface, potentially allowing a remote attacker to impact data integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Clickjacking

Weakness Enumeration

Related Identifiers

BDU:2022-04818
CVE-2022-20852

Affected Products

Cisco Webex Meetings