- Description
- A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have at least a low-privileged account on an affected device. Cisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
- Source
- ykramarz@cisco.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Primary
- Base score
- 5.4
- Impact score
- 2.7
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- ykramarz@cisco.com
- CWE-86
- Hype score
- Not currently trending
CVE-2025-20168 Cross-Site Scripting Vulnerability in Cisco CSPC's Web In... https://t.co/vuIshvF7qK Don't wait vulnerability scanning results: https://t.co/oh1APvMMnd
@VulmonFeeds
8 Jan 2025
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-20168 A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cros… https://t.co/OBlgG8eqFR
@CVEnew
8 Jan 2025
276 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes