XXE attack in Cisco WebEx Meetings Server - CVE-2018-18895
Published: November 12, 2018 / Updated: November 13, 2018
Cisco WebEx Meetings Server
Detailed vulnerability description
The vulnerability exists in the '/WBXServixe/XMLService' path name and 'siteName' parameters due to improper handling of XML External Entities (XXEs) when parsing an XML file. A remote attacker can trick the victim into open an XML file that submits malicious input and obtain potentially sensitive information.