Cross-Site Scripting Vulnerability in Cisco Unified Communications Manager
CVE-2025-20361
What is CVE-2025-20361?
A vulnerability in the web-based management interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition allows an authenticated remote attacker to execute cross-site scripting attacks. This situation arises due to inadequate validation of user input within the interface. By injecting malicious scripts into specific pages, attackers could potentially execute arbitrary code in the context of the interface or gain unauthorized access to sensitive browser information. Exploitation of this vulnerability requires possession of valid administrative credentials.
Affected Version(s)
Cisco Unified Communications Manager 12.5(1)SU2
Cisco Unified Communications Manager 12.5(1)SU1
Cisco Unified Communications Manager 12.5(1)