Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-34743

Опубликовано: 21 окт. 2021
Источник: nvd
CVSS3: 4.3
CVSS3: 7.1
CVSS2: 5.8
EPSS Низкий

Описание

A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an external application to integrate with and access a user's account without that user's express consent. This vulnerability is due to improper validation of cross-site request forgery (CSRF) tokens. An attacker could exploit this vulnerability by convincing a targeted user who is currently authenticated to Cisco Webex Software to follow a link designed to pass malicious input to the Cisco Webex Software application authorization interface. A successful exploit could allow the attacker to cause Cisco Webex Software to authorize an application on the user's behalf without the express consent of the user, possibly allowing external applications to read data from that user's profile.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:webex_meetings:-:*:*:*:*:*:*:*

EPSS

Процентиль: 45%
0.00229
Низкий

4.3 Medium

CVSS3

7.1 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-352
CWE-352

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an external application to integrate with and access a user's account without that user's express consent. This vulnerability is due to improper validation of cross-site request forgery (CSRF) tokens. An attacker could exploit this vulnerability by convincing a targeted user who is currently authenticated to Cisco Webex Software to follow a link designed to pass malicious input to the Cisco Webex Software application authorization interface. A successful exploit could allow the attacker to cause Cisco Webex Software to authorize an application on the user's behalf without the express consent of the user, possibly allowing external applications to read data from that user's profile.

CVSS3: 4.3
fstec
больше 4 лет назад

Уязвимость функции интеграции приложений программного обеспечения для веб-конференцсвязи Cisco Webex Meetings, позволяющая нарушителю осуществить межсайтовую подделку запросов

EPSS

Процентиль: 45%
0.00229
Низкий

4.3 Medium

CVSS3

7.1 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-352
CWE-352