CVE-2019-1680

A vulnerability in Cisco Webex Business Suite could allow an unauthenticated, remote attacker to inject arbitrary text into a user's browser. The vulnerability is due to improper validation of input. An attacker could exploit this vulnerability by convincing a targeted user to view a malicious URL. A successful exploit could allow the attacker to inject arbitrary text into the user's browser. The attacker could use the content injection to conduct spoofing attacks. Versions prior than 3.0.9 are affected.

Data: Cisco advisories · Cisco CSAF · NVD CVEs · NVD CPEs · CISA KEV · EPSS

SeverityMEDIUM
CVSS4.3
EPSS0.26% EPSS low
CWECWE-74
KEV
Published
Modified

Products with public affected evidence

Product Advisory Affected evidence
Cisco WebEx Meeting Center cisco-sa-20190206-webex-injection structured affected CSAF product_status