CVE-2021-1525
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to redirect users to a malicious file. This vulnerability is due to improper validation of URL paths in the application interface. An attacker could exploit this vulnerability by persuading a user to follow a specially crafted URL that is designed to cause Cisco Webex Meetings to include a remote file in the web UI. A successful exploit could allow the attacker to cause the application to offer a remote file to a user, which could allow the attacker to conduct further phishing or spoofing attacks.
EPSS 0.18% · 39.9th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | webex_meetings_online | 41.3.5 |
| cisco | webex_meetings_server | 0, 3.0, 3.0 |
| Cisco | Cisco WebEx Meetings Server | n/a |
Exploit Intelligence
Timeline
- Jun 4, 2021 CVE Published
- Jun 5, 2021 EPSS Score
- Aug 7, 2021 EPSS Score
- Oct 7, 2021 EPSS Score
- Dec 7, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 8, 2022 EPSS Score
- Jun 8, 2022 EPSS Score
- Aug 9, 2022 EPSS Score
- Oct 8, 2022 EPSS Score
- Dec 8, 2022 EPSS Score