Stored Cross-Site Scripting in Cisco Evolved Programmable Network Manager and Prime Infrastructure
CVE-2025-20280
What is CVE-2025-20280?
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure allows authenticated, remote attackers to execute stored cross-site scripting (XSS) attacks. This occurs due to improper validation of user-supplied input, enabling attackers to inject malicious scripts into specific data fields within the interface. If successfully exploited, this could allow arbitrary script code execution in the security context of the affected interface, potentially exposing sensitive browser-based information. Attackers must possess valid administrative credentials to exploit this vulnerability.
Affected Version(s)
Cisco Evolved Programmable Network Manager (EPNM) 8.0.0
Cisco Evolved Programmable Network Manager (EPNM) 8.0.0.1
Cisco Prime Infrastructure 3.0.0