CVE-2025-20129

MEDIUM

Cisco Customer Collaboration Platform - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the chat interface of a targeted user on a vulnerable server. A successful exploit could allow the attacker to redirect chat traffic to a server that is under their control, resulting in sensitive information being redirected to the attacker.

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 11.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (50)
cisco/socialminer 10.5\(1\)
cisco/socialminer 10.6\(1\)
cisco/socialminer 10.6\(2\)
cisco/socialminer 11.0\(1\)
cisco/socialminer 11.5\(1\)
cisco/socialminer 11.5\(1\)su1
cisco/socialminer 11.6\(1\)
cisco/socialminer 11.6\(2\)
cisco/socialminer 12.0\(1\)
cisco/socialminer 12.0\(1\)es02
... and 40 more
Published Jun 04, 2025
Tracked Since Feb 18, 2026