First published: Thu Jan 26 2017(Updated: )
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against an administrative user. More Information: CSCuz03317. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.12.
Credit: ykramarz@cisco.com psirt@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Webex Meetings Server | =2.6.0 | |
=2.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3794 has been rated as a medium severity vulnerability.
To fix CVE-2017-3794, upgrade Cisco WebEx Meetings Server to version 2.7.1.12 or later.
CVE-2017-3794 allows an unauthenticated remote attacker to conduct a cross-site request forgery (CSRF) attack.
Cisco WebEx Meetings Server version 2.6.0 is affected by CVE-2017-3794.
There are no documented workarounds for CVE-2017-3794; upgrading to a fixed release is recommended.