Stored Cross-Site Scripting Vulnerability in Cisco Enterprise Chat and Email
CVE-2025-20310
6.1MEDIUM
What is CVE-2025-20310?
A vulnerability in the web user interface of Cisco Enterprise Chat and Email permits an unauthenticated, remote attacker to execute stored cross-site scripting (XSS) attacks. This issue arises due to the inadequate validation of user-submitted input in the web interface. Attackers may exploit this flaw by enticing users to interact with a specially crafted link, leading to the execution of arbitrary script code or unauthorized access to sensitive information within the browser. To carry out this attack successfully, the attacker would require valid agent credentials.
Affected Version(s)
Cisco Enterprise Chat and Email 11.6(1)_ES3
Cisco Enterprise Chat and Email 11.6(1)_ES4
Cisco Enterprise Chat and Email 12.0(1)_ES6