CVE-2021-27770
12.05.2022, 22:15
The vulnerability was discovered within the FaviconService. The service takes a base64-encoded URL which is then requested by the webserver. We assume this service is used by the meetings-function where users can specify an external URL where the online meeting will take place.Enginsight
Vendor | Product | Version |
---|---|---|
hcltech | sametime | 11.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration