Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-1420

Опубликовано: 08 апр. 2021
Источник: nvd
CVSS3: 4.7
CVSS2: 4.3
EPSS Низкий

Описание

A vulnerability in certain web pages of Cisco Webex Meetings could allow an unauthenticated, remote attacker to modify a web page in the context of a user's browser. The vulnerability is due to improper checks on parameter values in affected pages. An attacker could exploit this vulnerability by persuading a user to follow a crafted link that is designed to pass HTML code into an affected parameter. A successful exploit could allow the attacker to alter the contents of a web page to redirect the user to potentially malicious websites, or the attacker could use this vulnerability to conduct further client-side attacks.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:webex_meetings:-:*:*:*:*:*:*:*

EPSS

Процентиль: 57%
0.00356
Низкий

4.7 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-80

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in certain web pages of Cisco Webex Meetings could allow an unauthenticated, remote attacker to modify a web page in the context of a user's browser. The vulnerability is due to improper checks on parameter values in affected pages. An attacker could exploit this vulnerability by persuading a user to follow a crafted link that is designed to pass HTML code into an affected parameter. A successful exploit could allow the attacker to alter the contents of a web page to redirect the user to potentially malicious websites, or the attacker could use this vulnerability to conduct further client-side attacks.

CVSS3: 4.7
fstec
почти 5 лет назад

Уязвимость программного обеспечения веб-конференцсвязи Cisco Webex Meetings, связанная с непринятием мер по нейтрализации script-related тэгов HTML на веб-странице, позволяющая нарушителю осуществить межсайтовые сценарные атаки

EPSS

Процентиль: 57%
0.00356
Низкий

4.7 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-80