Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-40128

Опубликовано: 04 нояб. 2021
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacker to send an account activation email with an activation link that points to an arbitrary domain. This vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by sending a crafted HTTP request to the account activation page of Cisco Webex Meetings. A successful exploit could allow the attacker to send to any recipient an account activation email that contains a tampered activation link, which could direct the user to an attacker-controlled website.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:webex_meetings:-:*:*:*:*:*:*:*

EPSS

Процентиль: 25%
0.00085
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-183
NVD-CWE-Other

Связанные уязвимости

CVSS3: 5.3
github
больше 3 лет назад

A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacker to send an account activation email with an activation link that points to an arbitrary domain. This vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by sending a crafted HTTP request to the account activation page of Cisco Webex Meetings. A successful exploit could allow the attacker to send to any recipient an account activation email that contains a tampered activation link, which could direct the user to an attacker-controlled website.

CVSS3: 5.3
fstec
больше 4 лет назад

Уязвимость функции активации учетной записи программного обеспечения веб-конференцсвязи Cisco Webex Meetings, позволяющая нарушителю отправить электронное письмо для активации учетной записи со ссылкой для активации, указывающей на произвольный домен

EPSS

Процентиль: 25%
0.00085
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-183
NVD-CWE-Other