Cisco Webex Meetings Cross-Site Scripting Vulnerability

🚨SEVERITY: MEDIUM — CVSS 5.4Security Advisory

TL;DR 📌

  • A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenticated, remote attacker with low privileges to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no customer action is needed. This vulnerability existed…
  • Highest CVSS: 5.4 (Medium).
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2025-20328.

What it is

CVE-2025-20328 is a cross-site scripting flaw in the user profile component of Cisco Webex Meetings. It stems from insufficient validation of user-supplied input in that component.

Exploitation required an authenticated attacker with low privileges to persuade a target user into clicking a crafted link. The resulting XSS would execute in the context of the targeted user’s session on the web-based Webex Meetings interface, potentially allowing the attacker to act against that user within the application.

This is a cloud-based service issue: Webex Meetings is delivered by Cisco as a hosted product, so the vulnerability existed in Cisco’s own infrastructure rather than in software deployed on customer premises.

What to do

  • No action is required. Cisco has already remediated this in the Webex Meetings cloud service itself.
  • There is no on-premises software or device update to apply, and no workaround was published — none was needed given the fix was applied service-side.
  • If you use Webex Meetings, you can treat this as closed; no version tracking or patch scheduling applies here.
  • For confirmation or to discuss any residual concerns, contact Cisco TAC or your contracted maintenance provider, as the advisory notes.

For leadership 🧭

Executive summary. This flaw allowed a logged-in attacker to run malicious script in another user’s Webex Meetings session by getting them to click a crafted link, but Cisco fixed it in the cloud service itself. There is no patch to schedule and no residual exposure to track.

Why it matters:

  • The flaw sits in the user profile component of Cisco’s hosted Webex Meetings, so it was corrected in Cisco’s infrastructure rather than in anything customers run locally
  • Exploitation needed an authenticated, low-privileged attacker to lure a target into clicking a crafted link, meaning it relied on social engineering rather than remote access alone
  • A successful attack executed script in the context of the targeted user’s own Webex session, letting an attacker act as that user within the application
  • No workaround was ever published because none was needed once Cisco applied the fix on the service side

Now / Next / Later:

  • Now: Confirm with your team that no local action is expected; Cisco has already remediated this in the cloud service and there is nothing to patch on your end.
  • Next: Skip any patch-scheduling or change-window work for this item since it applies to Cisco’s hosted infrastructure, not customer-managed systems.
  • Later: If you want confirmation or have residual questions, raise them with Cisco TAC or your contracted maintenance provider as the advisory suggests.

Source