CVE-2018-0390

CVE-2018-0390

A vulnerability in the web framework of Cisco Webex could allow an unauthenticated, remote attacker to conduct a Document Object Model-based (DOM-based) cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected software by using the HTTP POST method. An attacker who can submit malicious scripts to the affected user interface element could execute arbitrary script or HTML code in the user’s browser in the context of the affected site. Cisco Bug IDs: CSCvj33287.

Source: CVE-2018-0390

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다