{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T10:40:39Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"Cisco-SA-20071107-CVE-2007-5581","slug":"cisco-sa-20071107-cve-2007-5581","vendor":"Cisco","title":"Cisco Unified MeetingPlace Login Screen Cross-Site Scripting Vulnerability","summary":"Cisco Unified MeetingPlace versions 5.3.235.0 and prior, 5.4, and 6.0 contain a vulnerability that could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. This vulnerability is due to insufficient filtering of parameters passed to the Login form of Cisco Unified MeetingPlace.&nbsp; An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to follow a URL containing malicious parameters.&nbsp; When followed, the link could cause the affected site to return attacker-supplied script code to the affected user within the security context of the affected site.&nbsp; This could allow the attacker to execute arbitrary script code or HTML within a user's browser session.&nbsp; This could allow the attacker to gain access to sensitive browser information related to the affected site. Cisco has confirmed this vulnerability in a security response and released updated software. To exploit this vulnerability, an attacker must convince a user to follow a malicious URL, likely provided within an e-mail message or other form of messaging. An exploit could allow the attacker to execute arbitrary script code in the user's browser session within the Cisco Unified MeetingPlace application. An exploit could allow the attacker to gain access to sensitive browser-based information or possibly take actions on the affected site as the user. Because the affected login form is often deployed to facilitate remote web meetings between customers and the organization's deploying meeting place, it may be trivial for an attacker to convince a user of these systems to follow a crafted link. However, due to the nature of the application, the types of information an attacker may be able to disclose are limited in nature and are unlikely to pose a serious threat if disclosed. The Cisco Security Response has been updated with an additional bug ID and technical information, and additional updated software has been released. Administrators are advised to implement the fixes provided for both bug IDs to fully resolve this vulnerability.","severity":"Medium","published_at":"2007-11-07T14:56:25Z","updated_at":"2007-11-07T14:56:25Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20071107-CVE-2007-5581","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/Cisco-SA-20071107-CVE-2007-5581/csaf/Cisco-SA-20071107-CVE-2007-5581.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0,"highest_epss":0.01223},"cves":[{"id":"CVE-2007-5581","kev":false,"epss":{"score":0.01223,"percentile":0.65408,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"}}],"public_evidence":[{"product":{"name":"Cisco Unified MeetingPlace","slug":"cisco-unified-meetingplace","vendor":"Cisco"},"cve":{"id":"CVE-2007-5581"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T05:18:34Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco Unified MeetingPlace","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.01223,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"},"published_at":"2007-11-07T14:56:25Z","updated_at":"2007-11-07T14:56:25Z","advisory_updated_at":"2007-11-07T14:56:25Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20071107-CVE-2007-5581","row_display_order":1}]}