Stored Cross-Site Scripting Vulnerability in Cisco EPNM and Prime Infrastructure
CVE-2026-20075
What is CVE-2026-20075?
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure can potentially allow an authenticated remote attacker to execute stored cross-site scripting (XSS) attacks. This arises from the improper validation of user-supplied input in the management interface. By inserting malicious code into specific fields, an attacker with valid administrative credentials could exploit this weakness, resulting in the execution of arbitrary scripts within the affected interface or access to sensitive information stored in the browser. Protection against such vulnerabilities is crucial for maintaining system integrity and safeguarding user data.
Affected Version(s)
Cisco Evolved Programmable Network Manager (EPNM) 3.0.1
Cisco Evolved Programmable Network Manager (EPNM) 3.1.2
Cisco Evolved Programmable Network Manager (EPNM) 1.2
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved