CVE-2018-15461: Cisco Webex Business Suite Cross-Site Scripting Vulnerability
A vulnerability in the MyWebex component of Cisco Webex Business Suite could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by convincing a user to click a crafted URL. To exploit this vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the provided link.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15461?
CVE-2018-15461 is a vulnerability in the MyWebex component of Cisco Webex Business Suite that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack.
What is the severity of CVE-2018-15461?
CVE-2018-15461 has a severity rating of medium (6.1).
How can an attacker exploit CVE-2018-15461?
An attacker can exploit CVE-2018-15461 by convincing a user to visit a specially crafted website, which could execute arbitrary script code in the user's browser.
What is the affected software of CVE-2018-15461?
The affected software of CVE-2018-15461 is Cisco WebEx Business Suite.
How can I fix CVE-2018-15461?
To fix CVE-2018-15461, upgrade to the latest version of Cisco WebEx Business Suite.