CVE-2025-20330: Cisco Unified Communications Manager IM and Presence Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20330?
CVE-2025-20330 is rated as critical due to its potential to allow unauthenticated, remote attackers to execute cross-site scripting attacks.
How do I fix CVE-2025-20330?
To remediate CVE-2025-20330, update to the latest version of Cisco Unified Communications Manager IM & Presence Service as recommended by Cisco.
Who is affected by CVE-2025-20330?
CVE-2025-20330 affects users of the Cisco Unified Communications Manager IM & Presence Service web-based management interface.
What type of attack is associated with CVE-2025-20330?
CVE-2025-20330 is associated with cross-site scripting (XSS) attacks that can compromise user sessions and personal data.
Is authentication required to exploit CVE-2025-20330?
No, CVE-2025-20330 can be exploited by unauthenticated attackers, making it particularly dangerous.