#VU15811 XXE attack in Cisco WebEx Meetings Server - CVE-2018-18895
Published: November 12, 2018 / Updated: November 13, 2018
Cisco WebEx Meetings Server
Cisco Systems, Inc
Description
The vulnerability exists in the '/WBXServixe/XMLService' path name and 'siteName' parameters due to improper handling of XML External Entities (XXEs) when parsing an XML file. A remote attacker can trick the victim into open an XML file that submits malicious input and obtain potentially sensitive information.