CVE-2017-3799
published 2017-01-26CVE-2017-3799: A vulnerability in a URL parameter of Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to perform site redirection. More Information…
PriorityP426medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
1.02%
59.4th percentile
A vulnerability in a URL parameter of Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to perform site redirection. More Information: CSCzu78401. Known Affected Releases: T28.1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_meeting_center | — | — |
| cisco | webex_meeting_center_site_redirection | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qw6r-h4pp-rj89: A vulnerability in a URL parameter of Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to perform site redirection
ghsa_unreviewed·2022-05-17
CVE-2017-3799 [MEDIUM] CWE-601 GHSA-qw6r-h4pp-rj89: A vulnerability in a URL parameter of Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to perform site redirection
A vulnerability in a URL parameter of Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to perform site redirection. More Information: CSCzu78401. Known Affected Releases: T28.1.
Cisco
Cisco WebEx Meeting Center Site Redirection Vulnerability
vendor_cisco·2017-01-18·CVSS 5.0
CVE-2017-3799 [MEDIUM] CWE-22 Cisco WebEx Meeting Center Site Redirection Vulnerability
Cisco WebEx Meeting Center Site Redirection Vulnerability
A vulnerability in a URL parameter of Cisco WebEx could allow an unauthenticated, remote attacker to perform site redirection.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including a remote site URL in the affected parameter of the Cisco WebEx URL. An exploit could allow the attacker to redirect a user to a malicious website.
To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the provided link.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are available.
This advisory is avai
Cisco
Cisco WebEx Meeting Center Site Redirection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3799 Cisco WebEx Meeting Center Site Redirection Vulnerability
CVE-2017-3799: Cisco WebEx Meeting Center Site Redirection Vulnerability
A vulnerability in a URL parameter of Cisco WebEx could allow an unauthenticated, remote attacker to perform site redirection. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including a remote site URL in the affected parameter of the Cisco WebEx URL. An exploit could allow the attacker to redirect a user to a malicious website. To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the provided link. Cisco has released software updates that address this vulnerability.
CVSS: 3.0
CWE: CWE-22, CWE-22
Bug IDs: CSCzu78401
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/95642http://www.securitytracker.com/id/1037647https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170118-wms4http://www.securityfocus.com/bid/95642http://www.securitytracker.com/id/1037647https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170118-wms4
2017-01-26
Published