Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-26067— Cisco Webex Teams Web Interface Cross-Site Scripting Vulnerability

CVSS 5.4 · Medium EPSS 21.08% · P96
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-26067

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco Webex Teams Web Interface Cross-Site Scripting Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in the web-based interface of Cisco Webex Teams could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of usernames. An attacker could exploit this vulnerability by creating an account that contains malicious HTML or script content and joining a space using the malicious account name. A successful exploit could allow the attacker to conduct cross-site scripting attacks and potentially gain access to sensitive browser-based information.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
Web页面中脚本相关HTML标签转义处理不恰当(基本跨站脚本)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco?Webex Teams 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco?Webex Teams是美国思科(Cisco)公司的一款用于团队协作的软件。该软件可为团队提供线上沟通,拥有共享文件、数字白板、视频会议等功能。 Cisco Webex Teams中的web-based interface存在跨站脚本漏洞,该漏洞是由于用户名验证不正确引起的,成功的利用该漏洞可能使攻击者能够进行跨站点脚本攻击,并获取敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
CiscoCisco Webex Teams N/A -

II. Public POCs for CVE-2020-26067

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-26067

登录查看更多情报信息。

Same Patch Batch · Cisco · 2024-11-18 · 28 CVEs total

CVE-2020-271248.6 HIGHCisco Adaptive Security Appliance Software SSL/TLS Denial of Service Vulnerability
CVE-2020-260718.4 HIGHCisco SD-WAN vEdge Arbitrary File Creation Vulnerability
CVE-2020-260747.8 HIGHCisco SD-WAN vManage Privilege Escalation Vulnerability
CVE-2020-260737.5 HIGHCisco SD-WAN vManage Directory Traversal Vulnerability
CVE-2021-14406.8 MEDIUMCisco IOS XR Software BGP Resource Public Key Infrastructure Denial of Service Vulnerabili
CVE-2021-12326.5 MEDIUMCisco SD-WAN vManage Information Disclosure Vulnerability
CVE-2021-13796.5 MEDIUMCisco IP Phones Cisco Discovery Protocol and Link Layer Discovery Protocol Remote Code Exe
CVE-2020-35396.3 MEDIUMCisco Data Center Network Manager Authorization Bypass Vulnerability
CVE-2021-14446.1 MEDIUMCisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)
CVE-2020-34316.1 MEDIUMCisco Small Business RV Series Routers Cross-Site Scripting Vulnerability
CVE-2020-260635.4 MEDIUMCisco Integrated Management Controller Software Authorization Bypass Vulnerability
CVE-2020-260625.3 MEDIUMCisco Integrated Management Controller Username Enumeration Vulnerability
CVE-2021-14245.3 MEDIUMCisco ASR 5000 Series Software (StarOS) ipsecmgr Process Denial of Service Vulnerability
CVE-2021-11325.3 MEDIUMCisco Network Services Orchestrator Path Traversal Vulnerability
CVE-2021-12345.3 MEDIUMCisco SD-WAN vManage Information Disclosure Vulnerabilities
CVE-2020-35485.3 MEDIUMCisco Email Security Appliance Denial Of Service Vulnerability
CVE-2021-14614.9 MEDIUMCisco SD-WAN Software Signature Verification Bypass Vulnerability
CVE-2020-35384.6 MEDIUMCisco Data Center Network Manager Path Traversal Vulnerability
CVE-2021-14104.3 MEDIUMCisco Webex Meetings Unauthorized Distribution List Update Vulnerability
CVE-2021-14254.3 MEDIUMCisco Cisco Email Security Appliance and Content Security Management Appliance Informatio

Showing top 20 of 28 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2020-26067

No comments yet


Leave a comment