First published: Sat Dec 14 2013(Updated: )
The registration component in Cisco WebEx Training Center provides the training-session URL before e-mail confirmation is completed, which allows remote attackers to bypass intended access restrictions and join an audio conference by entering credential fields from this URL, aka Bug ID CSCul36183.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco WebEx Training Center |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6965 has a moderate severity rating due to its potential to allow unauthorized access to audio conferences.
To mitigate CVE-2013-6965, update your Cisco WebEx Training Center software to the latest version provided by Cisco.
CVE-2013-6965 exploits a flaw in the registration component that prematurely discloses training-session URLs before email confirmation.
Organizations using Cisco WebEx Training Center are affected by CVE-2013-6965, particularly those relying on the registration component.
CVE-2013-6965 allows remote attackers to bypass access restrictions and potentially join audio conferences within Cisco WebEx Training Center.