← Back

CVE-2023-20133

nvd nist
Published: Jul 7, 2023Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because of insufficient validation of user-supplied input in Webex Events (classic) programs, email templates, and survey questions. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

Affected (32)

1 product
Webex Meetings
Configuration A
32 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 39.10
Version 39.11
Version 39.6
Version 39.7.4
Version 39.7.7
Version 39.7
Version 39.8.2
Version 39.8.3
Version 39.8.4
Version 39.8
Version 39.9.1
Version 39.9
Version 40.1
Version 40.2
Version 40.4.10
Version 40.4
Version 40.6.2
Version 40.6
Version 42.10
Version 42.11
Version 42.12
Version 42.6
Version 42.7
Version 42.8
Version 42.9
Version 43.1
Version 43.2
Version 43.3
Version 43.4.1
Version 43.4.2
Version 43.4
Version 43.5.0

Timeline

No history available yet.