cisco-sa-webex-andro-iac-f3UR8frB: Cisco Webex Meetings for Android Avatar Modification Vulnerability
A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the Cisco Webex Meetings client of a targeted user of a meeting in which they are both participants. A successful exploit could allow the attacker to modify the avatar of the targeted user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-andro-iac-f3UR8frB
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-webex-andro-iac-f3UR8frB?
The severity of cisco-sa-webex-andro-iac-f3UR8frB is classified as medium.
What type of vulnerability is cisco-sa-webex-andro-iac-f3UR8frB?
cisco-sa-webex-andro-iac-f3UR8frB is an improper authorization vulnerability.
How can an attacker exploit cisco-sa-webex-andro-iac-f3UR8frB?
An attacker can exploit cisco-sa-webex-andro-iac-f3UR8frB by sending a crafted request to modify another user's avatar.
Which product is affected by cisco-sa-webex-andro-iac-f3UR8frB?
cisco-sa-webex-andro-iac-f3UR8frB affects the Cisco Webex Meetings Client for Android.
How do I fix cisco-sa-webex-andro-iac-f3UR8frB?
To fix cisco-sa-webex-andro-iac-f3UR8frB, users should update to the latest version of the Cisco Webex Meetings Client.