Cross-Site Scripting Vulnerability in Cisco Common Services Platform Collector
CVE-2025-20167
5.4MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 8 January 2025
Summary
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) allows an authenticated, remote attacker to perform cross-site scripting (XSS) attacks. This issue arises from inadequate validation of user-supplied input, enabling an attacker to inject malicious scripts into specific pages within the interface. Exploitation could lead to execution of arbitrary code in the context of the application or unauthorized access to sensitive data on the user's browser. To successfully execute the attack, the attacker needs to possess at least a low-privileged account on the affected device.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published