CVE-2018-15461
Cisco Webex Business Suite Cross-Site Scripting Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the MyWebex component of Cisco Webex Business Suite could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by convincing a user to click a crafted URL. To exploit this vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the provided link.
Una vulnerabilidad en el componente MyWebex en Cisco Webex Business Suite podría permitir que un atacante remoto no autenticado lleve a cabo un ataque de Cross-Site Scripting (XSS). Esta vulnerabilidad se debe a una validación insuficiente de las entradas realizadas por el usuario. Un atacante podría explotar esta vulnerabilidad convenciendo a un usuario para que haga clic en una URL manipulada. Para explotar esta vulnerabilidad, el atacante puede proporcionar un enlace que dirige al usuario a un sitio malicioso y emplear lenguaje o instrucciones engañosas para persuadirlo para que acceda al enlace proporcionado.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2018-08-17 CVE Reserved
- 2019-01-10 CVE Published
- 2024-11-19 EPSS Updated
- 2024-11-21 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/106505 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Webex Business Suite Search vendor "Cisco" for product "Webex Business Suite" | - | - |
Affected
|