ID

VAR-201810-0606


CVE

CVE-2018-15436


TITLE

plural Cisco Webex Product cross-site scripting vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-011167

DESCRIPTION

A vulnerability in the web-based management interface of Cisco Webex Events Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected service. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected service. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. plural Cisco Webex The product contains a cross-site scripting vulnerability.Information may be obtained and information may be altered. Cisco Webex Centers are prone to an cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug ID CSCvm14554. Cisco Webex Events Center and others are video conferencing solutions of Cisco (Cisco)

Trust: 1.98

sources: NVD: CVE-2018-15436 // JVNDB: JVNDB-2018-011167 // BID: 105557 // VULHUB: VHN-125695

AFFECTED PRODUCTS

vendor:ciscomodel:webex meetings onlinescope:eqversion:t33.4.0

Trust: 1.6

vendor:ciscomodel:webex business suite 33scope:gteversion:33.4.3

Trust: 1.0

vendor:ciscomodel:webex business suite 31scope:gteversion:31.29.2

Trust: 1.0

vendor:ciscomodel:webex business suite 32scope:gteversion:32.17.2

Trust: 1.0

vendor:ciscomodel:webex business suitescope: - version: -

Trust: 0.8

vendor:ciscomodel:webex meetings onlinescope: - version: -

Trust: 0.8

vendor:ciscomodel:webex business suite 33scope:eqversion:33.6

Trust: 0.6

vendor:ciscomodel:webex business suite 33scope:eqversion:33.5

Trust: 0.6

vendor:ciscomodel:webex business suite 31scope:eqversion:31.30

Trust: 0.6

vendor:ciscomodel:webex training centerscope:eqversion:0

Trust: 0.3

vendor:ciscomodel:webex support centerscope:eqversion:0

Trust: 0.3

vendor:ciscomodel:webex meeting centerscope:eqversion:0

Trust: 0.3

vendor:ciscomodel:webex events centerscope:eqversion:0

Trust: 0.3

sources: BID: 105557 // JVNDB: JVNDB-2018-011167 // CNNVD: CNNVD-201810-222 // NVD: CVE-2018-15436

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-15436
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-15436
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201810-222
value: MEDIUM

Trust: 0.6

VULHUB: VHN-125695
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-15436
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-125695
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-15436
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-125695 // JVNDB: JVNDB-2018-011167 // CNNVD: CNNVD-201810-222 // NVD: CVE-2018-15436

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-125695 // JVNDB: JVNDB-2018-011167 // NVD: CVE-2018-15436

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201810-222

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201810-222

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-011167

PATCH

title:cisco-sa-20181003-webex-xssurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181003-webex-xss

Trust: 0.8

title:Multiple Cisco Fixes for product cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=85436

Trust: 0.6

sources: JVNDB: JVNDB-2018-011167 // CNNVD: CNNVD-201810-222

EXTERNAL IDS

db:NVDid:CVE-2018-15436

Trust: 2.8

db:BIDid:105557

Trust: 2.0

db:SECTRACKid:1041793

Trust: 1.7

db:SECTRACKid:1041794

Trust: 1.7

db:JVNDBid:JVNDB-2018-011167

Trust: 0.8

db:CNNVDid:CNNVD-201810-222

Trust: 0.7

db:VULHUBid:VHN-125695

Trust: 0.1

sources: VULHUB: VHN-125695 // BID: 105557 // JVNDB: JVNDB-2018-011167 // CNNVD: CNNVD-201810-222 // NVD: CVE-2018-15436

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20181003-webex-xss

Trust: 2.0

url:http://www.securityfocus.com/bid/105557

Trust: 1.7

url:http://www.securitytracker.com/id/1041793

Trust: 1.7

url:http://www.securitytracker.com/id/1041794

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-15436

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-15436

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-125695 // BID: 105557 // JVNDB: JVNDB-2018-011167 // CNNVD: CNNVD-201810-222 // NVD: CVE-2018-15436

CREDITS

Cisco

Trust: 0.3

sources: BID: 105557

SOURCES

db:VULHUBid:VHN-125695
db:BIDid:105557
db:JVNDBid:JVNDB-2018-011167
db:CNNVDid:CNNVD-201810-222
db:NVDid:CVE-2018-15436

LAST UPDATE DATE

2024-11-23T22:48:33.752000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-125695date:2019-10-09T00:00:00
db:BIDid:105557date:2018-10-03T00:00:00
db:JVNDBid:JVNDB-2018-011167date:2019-01-08T00:00:00
db:CNNVDid:CNNVD-201810-222date:2019-10-17T00:00:00
db:NVDid:CVE-2018-15436date:2024-11-21T03:50:47.703

SOURCES RELEASE DATE

db:VULHUBid:VHN-125695date:2018-10-05T00:00:00
db:BIDid:105557date:2018-10-03T00:00:00
db:JVNDBid:JVNDB-2018-011167date:2019-01-08T00:00:00
db:CNNVDid:CNNVD-201810-222date:2018-10-08T00:00:00
db:NVDid:CVE-2018-15436date:2018-10-05T14:29:12.373