Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco Webex App for Web Cross-Site Scripting Vulnerability
Vulnerability Description
A vulnerability in the file upload functionality of Cisco Webex App for Web could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending an arbitrary file to a user and persuading that user to browse to a specific URL. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Cisco Webex 跨站脚本漏洞
Vulnerability Description
Cisco Webex是美国思科(Cisco)公司的一个视频会议和协作产品套件。 Cisco Webex App存在跨站脚本漏洞,该漏洞源于对用户提供的输入的验证不充分,存在文件上传漏洞,攻击者利用该漏洞可以进行跨站脚本(XSS)攻击。
CVSS Information
N/A
Vulnerability Type
N/A