NA

CVE-2023-20133

Published: 07/07/2023 Updated: 25/01/2024
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote malicious user to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because of insufficient validation of user-supplied input in Webex Events (classic) programs, email templates, and survey questions. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the malicious user to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco webex meetings 39.7.4

cisco webex meetings 39.10

cisco webex meetings 39.11

cisco webex meetings 39.6

cisco webex meetings 39.7

cisco webex meetings 39.7.7

cisco webex meetings 39.8

cisco webex meetings 39.8.2

cisco webex meetings 39.8.3

cisco webex meetings 39.8.4

cisco webex meetings 39.9

cisco webex meetings 39.9.1

cisco webex meetings 40.1

cisco webex meetings 40.2

cisco webex meetings 40.4

cisco webex meetings 40.4.10

cisco webex meetings 40.6

cisco webex meetings 40.6.2

cisco webex meetings 42.10

cisco webex meetings 42.11

cisco webex meetings 42.6

cisco webex meetings 42.9

cisco webex meetings 42.12

cisco webex meetings 42.8

cisco webex meetings 42.7

cisco webex meetings 43.2

cisco webex meetings 43.1

cisco webex meetings 43.3

cisco webex meetings 43.4

cisco webex meetings 43.4.2

cisco webex meetings 43.5.0

cisco webex meetings 43.4.1

Vendor Advisories

Multiple vulnerabilities in the web UI of Cisco Webex Meetings could allow a remote attacker to conduct stored cross-site scripting (XSS) or cross-site request forgery (CSRF) attacks For more information about these vulnerabilities, see the Details section of this advisory Cisco has released software updates that address these vulnerabilities Th ...