CVE-2014-3305Cross-Site Request Forgery in Cisco Webex Meetings Server

Severity
6.8MEDIUMNVD
EPSS
0.2%
top 59.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 26
Latest updateMay 17

Description

Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCuj81735.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

NVDcisco/webex_meetings_server1.5\(.1.131\)+2

🔴Vulnerability Details

2
GHSA
GHSA-7j3w-v628-x7hj: Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 12022-05-17
CVEList
CVE-2014-3305: Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 12014-07-26

📋Vendor Advisories

1
Cisco
Cisco WebEx Meetings Server Cross-Site Request Forgery Vulnerability2014-07-25
CVE-2014-3305 — Cross-Site Request Forgery in Cisco | cvebase