Vulnslist

find the latest Cisco vulnerabilities

Cisco Customer Collaboration Platform Information Disclosure Vulnerability

cisco-sa-ccp-info-disc-ZyGerQpd · Medium · Published · Updated

A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the chat interface of a targeted user on a vulnerable server. A successful exploit could allow the attacker to redirect chat traffic to a server that is under their control, resulting in sensitive information being redirected to the attacker. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ccp-info-disc-ZyGerQpd

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2025-20129
Cisco Bug IDsCSCwh43988
CVSS ScoreBase 4.3
Base 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Unified Contact Center Express, Cisco SocialMiner

Related Products

Product CVE Evidence
Cisco SocialMiner CVE-2025-20129 Cisco OpenVuln
Cisco Unified Contact Center CVE-2025-20129 Cisco OpenVuln
Cisco Unified Contact Center Express CVE-2025-20129 Cisco OpenVuln