CVE-2025-20279: Cisco Unifed Contact Center Express Stored Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to conduct a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper sanitization of user input to the web-based management interface. An attacker could exploit this vulnerability by submitting a malicious script through the interface. A successful exploit could allow the attacker to conduct a stored XSS attack on the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20279?
CVE-2025-20279 has a high severity rating due to the potential for authenticated remote attackers to execute stored XSS attacks.
How do I fix CVE-2025-20279?
To fix CVE-2025-20279, ensure that the affected Cisco Unified CCX system is updated with the latest security patches provided by Cisco.
Who is affected by CVE-2025-20279?
CVE-2025-20279 affects systems running the vulnerable version of Cisco Unified Contact Center Express with valid administrative access.
What type of attack is described in CVE-2025-20279?
CVE-2025-20279 describes a stored cross-site scripting (XSS) attack that can be conducted by authenticated users.
Can the CVE-2025-20279 vulnerability be exploited remotely?
Yes, CVE-2025-20279 can be exploited remotely by an authenticated attacker with valid administrative credentials.