CVE-2020-26067

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/11/2024
Last modified:
01/08/2025

Description

A vulnerability in the web-based interface of Cisco&amp;nbsp;Webex Teams could allow an authenticated, remote attacker to conduct cross-site scripting attacks.<br /> The vulnerability is due to improper validation of usernames. An attacker could exploit this vulnerability by creating an account that contains malicious HTML or script content and joining a space using the malicious account name. A successful exploit could allow the attacker to conduct cross-site scripting attacks and potentially gain access to sensitive browser-based information.Cisco&amp;nbsp;has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:webex_teams:*:*:*:*:*:*:*:*