CVE-2025-20129
MEDIUMCisco Customer Collaboration Platform - Info Disclosure
Title source: llmDescription
A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the chat interface of a targeted user on a vulnerable server. A successful exploit could allow the attacker to redirect chat traffic to a server that is under their control, resulting in sensitive information being redirected to the attacker.
References (1)
Core 1
Core References
Scores
CVSS v3
4.3
EPSS
0.0004
EPSS Percentile
11.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (50)
cisco/socialminer
10.5\(1\)
cisco/socialminer
10.6\(1\)
cisco/socialminer
10.6\(2\)
cisco/socialminer
11.0\(1\)
cisco/socialminer
11.5\(1\)
cisco/socialminer
11.5\(1\)su1
cisco/socialminer
11.6\(1\)
cisco/socialminer
11.6\(2\)
cisco/socialminer
12.0\(1\)
cisco/socialminer
12.0\(1\)es02
... and 40 more
Published
Jun 04, 2025
Tracked Since
Feb 18, 2026