CVE Database
/

CVE-2015-4262

Back to search

CVE-2015-4262

Published: Jul 24, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

The password-change feature in Cisco Unified MeetingPlace Web Conferencing before 8.5(5) MR3 and 8.6 before 8.6(2) does not check the session ID or require entry of the current password, which allows remote attackers to reset arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuu51839.

VendorProductVersions

n/a

n/a

affected
n/a

References

1033024
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now