CVE-2020-3345: Cisco Webex Meetings and Cisco Webex Meetings Server HTML Injection Vulnerability
A vulnerability in certain web pages of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to modify a web page in the context of a browser. The vulnerability is due to improper checks on parameter values within affected pages. An attacker could exploit this vulnerability by persuading a user to follow a crafted link that is designed to pass HTML code into an affected parameter. A successful exploit could allow the attacker to alter the contents of a web page to redirect the user to potentially malicious web sites, or the attacker could leverage this vulnerability to conduct further client-side attacks.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-3345?
CVE-2020-3345 is a vulnerability in certain web pages of Cisco Webex Meetings and Cisco Webex Meetings Server that could allow an unauthenticated, remote attacker to modify a web page in the context of a browser.
What software is affected by CVE-2020-3345?
The affected software includes Cisco Webex Meetings versions up to 40.6.0 and Cisco Webex Meetings Server versions up to 4.0-maintenance_release2.
How severe is CVE-2020-3345?
CVE-2020-3345 has a severity rating of 4.3, which is considered medium.
How can an attacker exploit CVE-2020-3345?
An attacker can exploit CVE-2020-3345 by taking advantage of improper checks on parameter values within affected web pages.
Where can I find more information about CVE-2020-3345?
You can find more information about CVE-2020-3345 on the Cisco Security Advisory page: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-html-BJ4Y9tX