Lucene search

K
cveCiscoCVE-2013-1245
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-1245

2022-10-0316:14:48
CWE-20
cisco
web.nvd.nist.gov
21
cve-2013-1245
cisco webex social
client-side validation
remote authenticated users
access restrictions
bug id cscue67190
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

30.1%

The user-management page in Cisco WebEx Social relies on client-side validation of values in the Screen Name, First Name, Middle Name, Last Name, Email Address, and Job Title fields, which allows remote authenticated users to bypass intended access restrictions via crafted requests, aka Bug ID CSCue67190.

Affected configurations

Nvd
Node
ciscowebex_socialMatch-
VendorProductVersionCPE
ciscowebex_social-cpe:/a:cisco:webex_social:-:::

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

30.1%

Related for CVE-2013-1245