First published: Sat Jul 26 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCuj81735.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Webex Meetings Server | <=1.5\(.1.131\) | |
Cisco Webex Meetings Server | =1.5 | |
Cisco Webex Meetings Server | =1.5\(.1.6\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3305 is categorized as a high severity vulnerability due to its potential to allow remote attackers to hijack user authentication.
To mitigate the risk of CVE-2014-3305, it is recommended to upgrade to a version of Cisco WebEx Meetings Server later than 1.5(.1.131).
CVE-2014-3305 affects Cisco WebEx Meetings Server versions 1.5 and earlier.
CVE-2014-3305 is a Cross-Site Request Forgery (CSRF) vulnerability.
Yes, CVE-2014-3305 can be exploited remotely by attackers to hijack victim authentication.