CVE-2022-20654
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2022-20654 is a vulnerability affecting the web-based interface of Cisco Webex Meetings. This issue allows an unauthenticated, remote attacker to carry out cross-site scripting (XSS) attacks on users of the interface. The root cause is insufficient input validation by the web-based interface. An attacker could trick a user into clicking a maliciously crafted link, potentially enabling them to execute arbitrary script code or gain access to sensitive browser-based information. Cisco has released software updates to rectify this vulnerability, and no workarounds are available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco WebEx Meetings
Affected Vendors
- Cisco Systems Inc