Improper input validation in Cisco WebEx Meeting Center - CVE-2017-12297
Published: December 1, 2017
Cisco WebEx Meeting Center
Detailed vulnerability description
The vulnerability allows a remote authenticated attacker to initiate connections to arbitrary hosts.
The vulnerability exists due to insufficient access control for HTTP traffic directed to the Cisco WebEx Meeting Center. A remote attacker can send a malicious URL to the Cisco WebEx Meeting Center and connect to arbitrary hosts.