Web-based chat interface vulnerability in Cisco Customer Collaboration Platform
CVE-2025-20129

4.3MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
4 June 2025

Badges

👾 Exploit Exists

What is CVE-2025-20129?

A vulnerability exists in the web-based chat interface of Cisco's Customer Collaboration Platform, enabling unauthenticated remote attackers to manipulate HTTP requests. Due to improper sanitization, attackers can forge requests that redirect chat traffic to their own servers. This redirection may lead to unauthorized disclosure of sensitive information from users engaged in chats on vulnerable servers. Organizations using affected versions of Cisco's CCP should ensure they address this vulnerability to protect user data from potential exploitation.

Affected Version(s)

Cisco SocialMiner 12.5(1)ES01

Cisco SocialMiner 10.5(1)

Cisco SocialMiner 11.6(1)

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20129 : Web-based chat interface vulnerability in Cisco Customer Collaboration Platform