CVE-2017-3811XML External Entity (XXE) Injection in Cisco Webex Meetings Server

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 44.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 17
Latest updateMay 17

Description

An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc39165. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.2054.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5cisco/cisco_webex_meetings_serverCisco WebEx Meetings Server

🔴Vulnerability Details

2
GHSA
GHSA-52pr-5rrw-jrw9: An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the i2022-05-17
CVEList
CVE-2017-3811: An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the i2017-03-17

💥Exploits & PoCs

1
Exploit-DB
WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injection2018-01-03

📋Vendor Advisories

1
Cisco
Cisco WebEx Meetings Server XML External Entity Vulnerability2017-03-15
CVE-2017-3811 — XML External Entity (XXE) Injection | cvebase