#VU17422 Cross-site scripting in Webex Meetings for Android - CVE-2019-1677
Published: February 7, 2019
Webex Meetings for Android
Cisco Systems, Inc
Description
The disclosed vulnerability allows a local authenticated attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A local attacker can send a malicious request to the Webex Meetings application through an intent and execute script code in the context of the Webex Meetings application.