QID 376975

Date Published: 2022-09-12

QID 376975: Cisco Webex Meetings App Character Interface Manipulation Vulnerability (cisco-sa-webex-app-qrtO6YC2)

A vulnerability in the messaging interface of Cisco Webex App, formerly Webex Teams, could allow an unauthenticated, remote attacker to manipulate links or other content within the messaging interface.

Affected Products
Cisco Webex App prior to Version 42.7

QID Detection Logic (Authenticated):
The QID checks for vulnerable version of Cisco Webex Meetings App by checking the version.

A successful exploit could allow the attacker to modify the display of links or other content within the interface, potentially allowing the attacker to conduct phishing or spoofing attacks.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-webex-app-qrtO6YC2 for more information.

    CVEs related to QID 376975

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-webex-app-qrtO6YC2 URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-app-qrtO6YC2