CVE-2023-20132

MEDIUM

Cisco Webex Meetings - Authenticated Stored Cross-Site Scripting and Arbitrary File Upload

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. For more information about these vulnerabilities, see the Details section of this advisory.

Scores

CVSS v3 5.4
EPSS 0.0020
EPSS Percentile 41.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-79
Status published
Products (1)
cisco/webex_meetings
Published Apr 05, 2023
Tracked Since Feb 18, 2026