HTML Injection Vulnerability in Cisco Secure Firewall Management Center Software
CVE-2025-20148
8.5HIGH
What is CVE-2025-20148?
A vulnerability exists within the web-based management interface of Cisco Secure Firewall Management Center Software. This flaw allows an authenticated remote attacker to inject arbitrary HTML into documents generated by the device. Due to improper validation of user-supplied data, an attacker with valid credentials can submit malicious content, altering the layout of official documents and potentially accessing sensitive files from the system. Additionally, this exploit could facilitate server-side request forgery (SSRF) attacks, further compromising the security of the affected system.
Affected Version(s)
Cisco Firepower Management Center 7.2.4
Cisco Firepower Management Center 7.0.6
Cisco Firepower Management Center 7.2.4.1