Web-based chat interface vulnerability in Cisco Customer Collaboration Platform
CVE-2025-20129
4.3MEDIUM
What is CVE-2025-20129?
A vulnerability exists in the web-based chat interface of Cisco's Customer Collaboration Platform, enabling unauthenticated remote attackers to manipulate HTTP requests. Due to improper sanitization, attackers can forge requests that redirect chat traffic to their own servers. This redirection may lead to unauthorized disclosure of sensitive information from users engaged in chats on vulnerable servers. Organizations using affected versions of Cisco's CCP should ensure they address this vulnerability to protect user data from potential exploitation.
Affected Version(s)
Cisco SocialMiner 12.5(1)ES01
Cisco SocialMiner 10.5(1)
Cisco SocialMiner 11.6(1)