Cross-Site Scripting Vulnerability in Cisco Unified Communications Manager
CVE-2025-20361

4.8MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
1 October 2025

Badges

👾 Exploit Exists

What is CVE-2025-20361?

A vulnerability in the web-based management interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition allows an authenticated remote attacker to execute cross-site scripting attacks. This situation arises due to inadequate validation of user input within the interface. By injecting malicious scripts into specific pages, attackers could potentially execute arbitrary code in the context of the interface or gain unauthorized access to sensitive browser information. Exploitation of this vulnerability requires possession of valid administrative credentials.

Affected Version(s)

Cisco Unified Communications Manager 12.5(1)SU2

Cisco Unified Communications Manager 12.5(1)SU1

Cisco Unified Communications Manager 12.5(1)

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20361 : Cross-Site Scripting Vulnerability in Cisco Unified Communications Manager