CVE Database
/

CVE-2025-20129

Back to search

CVE-2025-20129

Published: Jun 4, 2025

Modified: Jun 4, 2025

PUBLISHED

CVSS v3.1

4.3

MEDIUM

Description

A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the chat interface of a targeted user on a vulnerable server. A successful exploit could allow the attacker to redirect chat traffic to a server that is under their control, resulting in sensitive information being redirected to the attacker.

VendorProductVersions

Cisco

Cisco SocialMiner

affected
12.5(1)ES01
affected
10.5(1)
affected
11.6(1)
affected
10.6(1)
affected
12.0(1)ES04

+12 more versions

Cisco

Cisco Unified Contact Center Express

affected
10.6(1)
affected
10.5(1)SU1
affected
10.6(1)SU3
affected
12.0(1)
affected
10.0(1)SU1

+55 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

None

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now