Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-1525


A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to redirect users to a malicious file. This vulnerability is due to improper validation of URL paths in the application interface. An attacker could exploit this vulnerability by persuading a user to follow a specially crafted URL that is designed to cause Cisco Webex Meetings to include a remote file in the web UI. A successful exploit could allow the attacker to cause the application to offer a remote file to a user, which could allow the attacker to conduct further phishing or spoofing attacks.


Published

2021-06-04T17:15:08.533

Last Modified

2024-11-21T05:44:32.863

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.7 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-601

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco webex_meetings_online 41.3.5 Yes
Application cisco webex_meetings_server < 3.0 Yes
Application cisco webex_meetings_server 3.0 Yes
Application cisco webex_meetings_server 3.0 Yes
Application cisco webex_meetings_server 3.0 Yes
Application cisco webex_meetings_server 3.0 Yes
Application cisco webex_meetings_server 4.0 Yes
Application cisco webex_meetings_server 4.0 Yes
Application cisco webex_meetings_server 4.0 Yes
Application cisco webex_meetings_server 4.0 Yes
Application cisco webex_meetings_server 4.0 Yes
Application cisco webex_meetings_server 4.0 Yes

References