user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708.
| Software | From | Fixed in |
|---|---|---|
| cisco / webex_meetings_server | 1.5(.1.6) | 1.5(.1.6).x |
| cisco / webex_meetings_server | 1.5 | 1.5.x |
| cisco / webex_meetings_server | - | 1.5\(.1.131\).x |