Cisco Webex Meetings Cross-Site Scripting Vulnerability
TL;DR 📌
- A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenticated, remote attacker with low privileges to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no customer action is needed. This vulnerability existed…
- Highest CVSS: 5.4 (Medium).
- Check the advisory for fixed releases — remediation detail is in the vendor link below.
- CVEs: CVE-2025-20328.
What it is
CVE-2025-20328 is a cross-site scripting flaw in the user profile component of Cisco Webex Meetings. It stems from insufficient validation of user-supplied input in that component.
Exploitation required an authenticated attacker with low privileges to persuade a target user into clicking a crafted link. The resulting XSS would execute in the context of the targeted user’s session on the web-based Webex Meetings interface, potentially allowing the attacker to act against that user within the application.
This is a cloud-based service issue: Webex Meetings is delivered by Cisco as a hosted product, so the vulnerability existed in Cisco’s own infrastructure rather than in software deployed on customer premises.
What to do
- No action is required. Cisco has already remediated this in the Webex Meetings cloud service itself.
- There is no on-premises software or device update to apply, and no workaround was published — none was needed given the fix was applied service-side.
- If you use Webex Meetings, you can treat this as closed; no version tracking or patch scheduling applies here.
- For confirmation or to discuss any residual concerns, contact Cisco TAC or your contracted maintenance provider, as the advisory notes.
For leadership ðŸ§
Executive summary. This flaw allowed a logged-in attacker to run malicious script in another user’s Webex Meetings session by getting them to click a crafted link, but Cisco fixed it in the cloud service itself. There is no patch to schedule and no residual exposure to track.
Why it matters:
- The flaw sits in the user profile component of Cisco’s hosted Webex Meetings, so it was corrected in Cisco’s infrastructure rather than in anything customers run locally
- Exploitation needed an authenticated, low-privileged attacker to lure a target into clicking a crafted link, meaning it relied on social engineering rather than remote access alone
- A successful attack executed script in the context of the targeted user’s own Webex session, letting an attacker act as that user within the application
- No workaround was ever published because none was needed once Cisco applied the fix on the service side
Now / Next / Later:
- Now: Confirm with your team that no local action is expected; Cisco has already remediated this in the cloud service and there is nothing to patch on your end.
- Next: Skip any patch-scheduling or change-window work for this item since it applies to Cisco’s hosted infrastructure, not customer-managed systems.
- Later: If you want confirmation or have residual questions, raise them with Cisco TAC or your contracted maintenance provider as the advisory suggests.