Vulnslist

find the latest Cisco vulnerabilities

Cisco Spark Messaging Stored Cross-Site Scripting Vulnerability

cisco-sa-20171004-sprk · Medium · Published · Updated

A vulnerability in the web UI of Cisco Spark Messaging Software could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. The vulnerability is due to insufficient input validation by the web UI of the affected software. An attacker could exploit this vulnerability by injecting XSS content into the web UI of the affected software. A successful exploit could allow the attacker to force a user to execute code of the attacker's choosing or allow the attacker to retrieve sensitive information from the user. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171004-sprk

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2017-12269
Cisco Bug IDsCSCvf70587, CSCvf70592
CVSS ScoreBase 5.4
Base 5.4 CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Webex Teams, Cisco Webex App

Related Products

Product CVE Evidence
Cisco Webex Teams CVE-2017-12269 Cisco OpenVuln
Cisco Webex App CVE-2017-12269 Cisco OpenVuln