Stored Cross-Site Scripting in Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure
CVE-2025-20120
Summary
A vulnerability exists in the web-based management interface of Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure, where insufficient validation of user-supplied input allows for stored cross-site scripting (XSS) attacks. This flaw enables an unauthenticated, remote attacker to inject malicious scripts into specific pages of the interface. If successfully executed, this could allow the attacker to run arbitrary script code within the context of the affected interface, potentially exposing sensitive browser-based information to unauthorized access. Users and organizations utilizing these systems are advised to implement security measures to mitigate this risk.
Affected Version(s)
Cisco Evolved Programmable Network Manager (EPNM) 1.2.6
Cisco Evolved Programmable Network Manager (EPNM) 1.2.2
Cisco Evolved Programmable Network Manager (EPNM) 1.2.3
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved