CVE-2025-20203

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Apr 2, 2025
Updated: Apr 7, 2025
CWE ID 79

Summary

CVE-2025-20203 is a stored XSS vulnerability affecting the web-based management interfaces of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure. An authenticated, remote attacker can exploit this flaw by inserting malicious code into specific data fields, allowing them to execute arbitrary script code or gain access to sensitive browser-based information. The vulnerability stems from the interfaces' failure to adequately validate user-supplied input. Successful exploitation requires the attacker to have valid administrative credentials.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share