CNNVD-202509-255 Information

CNNVD ID

CNNVD-202509-255

CVE-2025-20330

  • CNNVD Published: 2025-09-03

Description (Chinese)

Cisco Unified Communications Manager IM & Presence是美国思科(Cisco)公司的一个整合通讯软件。 Cisco Unified Communications Manager IM & Presence存在跨站脚本漏洞,该漏洞源于对用户输入验证不当,可能导致跨站脚本攻击。

Description (English)

Cisco United Communications Manager IM & Presence is an integrated communications software for Cisco. Cisco United Commissions Manager IM & Presence had a cross-site script loophole, which stemmed from improper verification of user input and could lead to a cross-site script attack.

Hazard Level

High

Vulnerability Type

跨站脚本

Affected Vendor

Citadel

Published

2025-09-03

Last Modified

2026-02-24

References

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-imp-xss-XQgu4HSG https://vigilance.fr/vulnerability/Cisco-Unified-Communications-Manager-Cross-Site-Scripting-via-Management-Interface-48126

Patch

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-imp-xss-XQgu4HSG

Share on: