CVE-2022-20654

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Nov 15, 2024
CWE ID 80

Summary

CVE-2022-20654 is a vulnerability affecting the web-based interface of Cisco Webex Meetings. This issue allows an unauthenticated, remote attacker to carry out cross-site scripting (XSS) attacks on users of the interface. The root cause is insufficient input validation by the web-based interface. An attacker could trick a user into clicking a maliciously crafted link, potentially enabling them to execute arbitrary script code or gain access to sensitive browser-based information. Cisco has released software updates to rectify this vulnerability, and no workarounds are available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco WebEx Meetings

Affected Vendors

  • Cisco Systems Inc