CVE-2018-0390: XSS
A vulnerability in the web framework of Cisco Webex could allow an unauthenticated, remote attacker to conduct a Document Object Model-based (DOM-based) cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected software by using the HTTP POST method. An attacker who can submit malicious scripts to the affected user interface element could execute arbitrary script or HTML code in the user's browser in the context of the affected site. Cisco Bug IDs: CSCvj33287.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0390?
CVE-2018-0390 is rated as a high severity vulnerability due to its potential to enable DOM-based cross-site scripting (XSS) attacks.
How do I fix CVE-2018-0390?
To mitigate CVE-2018-0390, users should upgrade to a patched version of Cisco Webex Meetings Client.
What affects CVE-2018-0390?
CVE-2018-0390 specifically affects version 2.0 of Cisco Webex Meetings Client.
Can CVE-2018-0390 be exploited remotely?
Yes, CVE-2018-0390 can be exploited by an unauthenticated remote attacker.
What type of attack is associated with CVE-2018-0390?
CVE-2018-0390 is associated with a Document Object Model-based (DOM) cross-site scripting (XSS) attack.