Back

MEDIUM

Cisco Webex App for Web Cross-Site Scripting Vulnerability

Published Mar 3, 2023

Description

A vulnerability in the file upload functionality of Cisco Webex App for Web could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending an arbitrary file to a user and persuading that user to browse to a specific URL. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner cisco
Published Mar 3, 2023
Updated Oct 25, 2024
Reserved Oct 27, 2022
CISA Vulnrichment
Updated Oct 25, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner cisco
Published Mar 3, 2023
Updated Oct 25, 2024
Exploited since n/a
EUVD-2023-24283