Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m9p9-grq9-ph27

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the Cisco Webex Meetings client of a targeted user of a meeting in which they are both participants. A successful exploit could allow the attacker to modify the avatar of the targeted user.

A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the Cisco Webex Meetings client of a targeted user of a meeting in which they are both participants. A successful exploit could allow the attacker to modify the avatar of the targeted user.

EPSS

Процентиль: 29%
0.00107
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-269
CWE-284

Связанные уязвимости

CVSS3: 4.3
nvd
почти 5 лет назад

A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the Cisco Webex Meetings client of a targeted user of a meeting in which they are both participants. A successful exploit could allow the attacker to modify the avatar of the targeted user.

CVSS3: 4.3
fstec
почти 5 лет назад

Уязвимость программного обеспечения для веб-конференцсвязи Cisco Webex Meetings для Android, связанная с недостатками контроля доступа, позволяющая нарушителю изменить аватар целевого пользователя

EPSS

Процентиль: 29%
0.00107
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-269
CWE-284