A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
This vulnerability exists because of insufficient validation of user-supplied input in Webex Events (classic) programs, email templates, and survey questions. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:40
Type | Values Removed | Values Added |
---|---|---|
References | () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sxsscsrf-2L24bBx6 - Vendor Advisory |
18 Jul 2023, 17:59
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:cisco:webex_meetings:42.11:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:40.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:43.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:39.8.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:39.8:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:40.6:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:42.9:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:40.4:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:42.8:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:43.5.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:43.4:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:43.4.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:43.4.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:42.7:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:40.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:39.9.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:39.7.7:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:42.12:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:39.8.3:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:39.7:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:39.9:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:42.6:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:40.4.10:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:39.6:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:39.10:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:39.7.4:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:39.8.4:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:42.10:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:43.3:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:43.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:40.6.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:39.11:*:*:*:*:*:*:* |
|
References | (MISC) https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sxsscsrf-2L24bBx6 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
First Time |
Cisco
Cisco webex Meetings |
|
CWE | CWE-79 |
07 Jul 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-07 20:15
Updated : 2024-11-21 07:40
NVD link : CVE-2023-20133
Mitre link : CVE-2023-20133
CVE.ORG link : CVE-2023-20133
JSON object : View
Products Affected
cisco
- webex_meetings
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')