{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T10:00:19Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"Cisco-SA-20130515-CVE-2013-1245","slug":"cisco-sa-20130515-cve-2013-1245","vendor":"Cisco","title":"Cisco WebEx Social Client-Side Restriction Bypass Attribute Change Vulnerability","summary":"A vulnerability in the user management page of WebEx Social could allow an authenticated, remote attacker to inject arbitrary values into the Screen Name, Email Address, First Name, Middle Name, Last Name, and Job Title fields. The vulnerability is due to insufficient server-side validation of user-supplied information. An attacker could exploit this vulnerability by bypassing client-side protections to insert arbitrary values into the vulnerable fields. Cisco has confirmed the vulnerability in a security notice and has released software updates. To exploit this vulnerability, an attacker would require authenticated access to the targeted device, and may require access to trusted, internal networks. These access requirements could limit the likelihood of a successful exploit. Cisco indicates through the CVSS score that the vulnerability is highly exploitable; however, exploit code is not known to be publicly available.","severity":"Medium","published_at":"2013-05-15T19:21:09Z","updated_at":"2013-05-15T19:21:09Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20130515-CVE-2013-1245","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/Cisco-SA-20130515-CVE-2013-1245/csaf/Cisco-SA-20130515-CVE-2013-1245.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0,"highest_epss":0.00997},"cves":[{"id":"CVE-2013-1245","kev":false,"epss":{"score":0.00997,"percentile":0.58796,"score_date":"2026-07-19","updated_at":"2026-07-20T05:46:47Z"}}],"public_evidence":[{"product":{"name":"Cisco WebEx Social","slug":"cisco-webex-social","vendor":"Cisco"},"cve":{"id":"CVE-2013-1245"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T05:24:24Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco WebEx Social","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.00997,"score_date":"2026-07-19","updated_at":"2026-07-20T05:46:47Z"},"published_at":"2013-05-15T19:21:09Z","updated_at":"2013-05-15T19:21:09Z","advisory_updated_at":"2013-05-15T19:21:09Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20130515-CVE-2013-1245","row_display_order":1}]}