CVE-2022-20863CWE-450

Cisco Webex Meetings App Character Interface Manipulation Vulnerability

Medium · published September 8, 2022

CVSS v3.1
4.3
EPSS
1%
Percentile
56.1
In the wild
Unconfirmed
What it is

A vulnerability in the messaging interface of Cisco Webex App, formerly Webex Teams, could allow an unauthenticated, remote attacker to manipulate links or other content within the messaging interface. This vulnerability exists because the affected software does not properly handle character rendering. An attacker could exploit this vulnerability by sending messages within the application interface. A successful exploit could allow the attacker to modify the display of links or other content within the interface, potentially allowing the attacker to conduct phishing or spoofing attacks.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00857 · 56.1th percentile
Weakness
CWE-450 · Multiple Interpretations of UI Input
Published
2022-09-08T12:30Z
EPSS history
Timeline
  • 08 SEP 12:30Z
    Cisco Webex Meetings App Character Interface Manipulation Vulnerability
    cvelistv5