Cross-Site Scripting Vulnerability in Cisco Common Services Platform Collector
CVE-2025-20167
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 8 January 2025
What is CVE-2025-20167?
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) allows an authenticated, remote attacker to perform cross-site scripting (XSS) attacks. This issue arises from inadequate validation of user-supplied input, enabling an attacker to inject malicious scripts into specific pages within the interface. Exploitation could lead to execution of arbitrary code in the context of the application or unauthorized access to sensitive data on the user's browser. To successfully execute the attack, the attacker needs to possess at least a low-privileged account on the affected device.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published