Back

MEDIUM

Cisco Webex Training Unauthorized Meeting Join Vulnerability

Published Sep 4, 2020

Description

A vulnerability in Cisco Webex Training could allow an authenticated, remote attacker to join a password-protected meeting without providing the meeting password. The vulnerability is due to improper validation of input to API requests that are a part of meeting join flow. An attacker could exploit this vulnerability by sending an API request to the application, which would return a URL that includes a meeting join page that is prepopulated with the meeting username and password. A successful exploit could allow the attacker to join the password-protected meeting. The attacker would be visible in the attendee list of the meeting.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner cisco
Published Sep 4, 2020
Updated Nov 13, 2024
Reserved Dec 12, 2019

CISA Vulnrichment

Updated Nov 13, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner cisco
Published Sep 4, 2020
Updated Nov 13, 2024

GitHub

No data