Cisco-SA-20150622-CVE-2015-4210

Cisco WebEx Meetings Reflected Cross-Site Scripting Vulnerability

Medium · Updated · Cisco

1 product with CSAF evidence

A vulnerability in Cisco WebEx Meetings could allow an unauthenticated, remote attacker to perform reflected cross-site scripting attacks. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted URL that is designed to submit malicious code to the affected software. Cisco has confirmed the vulnerability and released software updates. To exploit the vulnerability, the attacker may provide a link to the user and convince the user to follow the link by using misleading language and instructions.