Stored Cross-Site Scripting Vulnerability in Cisco Enterprise Chat and Email
CVE-2025-20310

6.1MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
2 July 2025

Badges

👾 Exploit Exists

What is CVE-2025-20310?

A vulnerability in the web user interface of Cisco Enterprise Chat and Email permits an unauthenticated, remote attacker to execute stored cross-site scripting (XSS) attacks. This issue arises due to the inadequate validation of user-submitted input in the web interface. Attackers may exploit this flaw by enticing users to interact with a specially crafted link, leading to the execution of arbitrary script code or unauthorized access to sensitive information within the browser. To carry out this attack successfully, the attacker would require valid agent credentials.

Affected Version(s)

Cisco Enterprise Chat and Email 11.6(1)_ES3

Cisco Enterprise Chat and Email 11.6(1)_ES4

Cisco Enterprise Chat and Email 12.0(1)_ES6

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20310 : Stored Cross-Site Scripting Vulnerability in Cisco Enterprise Chat and Email