First published: Thu Jan 10 2019(Updated: )
A vulnerability in the MyWebex component of Cisco Webex Business Suite could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by convincing a user to click a crafted URL. To exploit this vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the provided link.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco WebEx Business Suite |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15461 is a vulnerability in the MyWebex component of Cisco Webex Business Suite that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack.
CVE-2018-15461 has a severity rating of medium (6.1).
An attacker can exploit CVE-2018-15461 by convincing a user to visit a specially crafted website, which could execute arbitrary script code in the user's browser.
The affected software of CVE-2018-15461 is Cisco WebEx Business Suite.
To fix CVE-2018-15461, upgrade to the latest version of Cisco WebEx Business Suite.