Логотип exploitDog
bind:CVE-2021-40128
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-40128

Количество 3

Количество 3

nvd логотип

CVE-2021-40128

больше 4 лет назад

A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacker to send an account activation email with an activation link that points to an arbitrary domain. This vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by sending a crafted HTTP request to the account activation page of Cisco Webex Meetings. A successful exploit could allow the attacker to send to any recipient an account activation email that contains a tampered activation link, which could direct the user to an attacker-controlled website.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-f5wr-xjgr-jhq9

больше 3 лет назад

A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacker to send an account activation email with an activation link that points to an arbitrary domain. This vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by sending a crafted HTTP request to the account activation page of Cisco Webex Meetings. A successful exploit could allow the attacker to send to any recipient an account activation email that contains a tampered activation link, which could direct the user to an attacker-controlled website.

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2021-06164

больше 4 лет назад

Уязвимость функции активации учетной записи программного обеспечения веб-конференцсвязи Cisco Webex Meetings, позволяющая нарушителю отправить электронное письмо для активации учетной записи со ссылкой для активации, указывающей на произвольный домен

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-40128

A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacker to send an account activation email with an activation link that points to an arbitrary domain. This vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by sending a crafted HTTP request to the account activation page of Cisco Webex Meetings. A successful exploit could allow the attacker to send to any recipient an account activation email that contains a tampered activation link, which could direct the user to an attacker-controlled website.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-f5wr-xjgr-jhq9

A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacker to send an account activation email with an activation link that points to an arbitrary domain. This vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by sending a crafted HTTP request to the account activation page of Cisco Webex Meetings. A successful exploit could allow the attacker to send to any recipient an account activation email that contains a tampered activation link, which could direct the user to an attacker-controlled website.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2021-06164

Уязвимость функции активации учетной записи программного обеспечения веб-конференцсвязи Cisco Webex Meetings, позволяющая нарушителю отправить электронное письмо для активации учетной записи со ссылкой для активации, указывающей на произвольный домен

CVSS3: 5.3
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу