4.8

CVE-2025-20361

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.

This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerCisco
Produkt Cisco Unified Communications Manager
Default Statusunknown
Version 12.5(1)SU2
Status affected
Version 12.5(1)SU1
Status affected
Version 12.5(1)
Status affected
Version 12.5(1)SU3
Status affected
Version 12.5(1)SU4
Status affected
Version 14
Status affected
Version 12.5(1)SU5
Status affected
Version 14SU1
Status affected
Version 12.5(1)SU6
Status affected
Version 14SU2
Status affected
Version 12.5(1)SU7
Status affected
Version 12.5(1)SU7a
Status affected
Version 14SU3
Status affected
Version 12.5(1)SU8
Status affected
Version 12.5(1)SU8a
Status affected
Version 15
Status affected
Version 15SU1
Status affected
Version 14SU4
Status affected
Version 14SU4a
Status affected
Version 15SU1a
Status affected
Version 12.5(1)SU9
Status affected
Version 15SU2
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.097
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@cisco.com 4.8 1.7 2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.