Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco Webex Teams Web Interface Cross-Site Scripting Vulnerability
Vulnerability Description
A vulnerability in the web-based interface of Cisco Webex Teams could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of usernames. An attacker could exploit this vulnerability by creating an account that contains malicious HTML or script content and joining a space using the malicious account name. A successful exploit could allow the attacker to conduct cross-site scripting attacks and potentially gain access to sensitive browser-based information.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
Web页面中脚本相关HTML标签转义处理不恰当(基本跨站脚本)
Vulnerability Title
Cisco?Webex Teams 跨站脚本漏洞
Vulnerability Description
Cisco?Webex Teams是美国思科(Cisco)公司的一款用于团队协作的软件。该软件可为团队提供线上沟通,拥有共享文件、数字白板、视频会议等功能。 Cisco Webex Teams中的web-based interface存在跨站脚本漏洞,该漏洞是由于用户名验证不正确引起的,成功的利用该漏洞可能使攻击者能够进行跨站点脚本攻击,并获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A