← Back

CVE-2020-3345

nvd nist
Published: Jul 16, 2020Modified: Nov 21, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

A vulnerability in certain web pages of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to modify a web page in the context of a browser. The vulnerability is due to improper checks on parameter values within affected pages. An attacker could exploit this vulnerability by persuading a user to follow a crafted link that is designed to pass HTML code into an affected parameter. A successful exploit could allow the attacker to alter the contents of a web page to redirect the user to potentially malicious web sites, or the attacker could leverage this vulnerability to conduct further client-side attacks.

Affected (5)

2 products
Webex Meetings
Webex Meetings Server
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Before 40.6.0
Cisco
Up to 4.0
Version 4.0
Version 4.0 maintenance_release1
Version 4.0 maintenance_release2

Timeline

No history available yet.