Stored Cross-Site Scripting Vulnerability in Cisco Evolved Programmable Network Manager and Prime Infrastructure
CVE-2025-20203
Summary
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure enables an authenticated remote attacker to perform a stored cross-site scripting (XSS) attack. This occurs due to inadequate validation of user-supplied input, allowing an attacker with administrative access to embed malicious scripts into specific data fields. When successfully executed, these scripts can run in the context of an affected interface, posing risks such as the unauthorized access to sensitive browser-based information.
Affected Version(s)
Cisco Evolved Programmable Network Manager (EPNM) 1.2.6
Cisco Evolved Programmable Network Manager (EPNM) 1.2.2
Cisco Evolved Programmable Network Manager (EPNM) 1.2.3
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved