Vulnerability Details CVE-2021-27770
The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We assume this service is used by the “meetings”-function where users can specify an external URL where the online meeting will take place.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.7%
CVSS Severity
CVSS v3 Score 6.8
CVSS v2 Score 6.8
Products affected by CVE-2021-27770
-
cpe:2.3:a:hcltech:sametime:11.6