CVE-2025-20129
published 2025-06-04CVE-2025-20129: A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated…
PriorityP430medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.32%
24.0th percentile
A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data.
This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the chat interface of a targeted user on a vulnerable server. A successful exploit could allow the attacker to redirect chat traffic to a server that is under their control, resulting in sensitive information being redirected to the attacker.
Affected
155 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_socialminer | — | — |
| cisco | cisco_socialminer | — | — |
| cisco | cisco_socialminer | — | — |
| cisco | cisco_socialminer | — | — |
| cisco | cisco_socialminer | — | — |
| cisco | cisco_socialminer | — | — |
| cisco | cisco_socialminer | — | — |
| cisco | cisco_socialminer | — | — |
| cisco | cisco_socialminer | — | — |
| cisco | cisco_socialminer | — | — |
| cisco | cisco_socialminer | — | — |
| cisco | cisco_socialminer | — | — |
| cisco | cisco_socialminer | — | — |
| cisco | cisco_socialminer | — | — |
| cisco | cisco_socialminer | — | — |
| cisco | cisco_socialminer | — | — |
| cisco | cisco_socialminer | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xpgj-x2hj-7mq2: A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthentic
ghsa_unreviewed·2025-06-04
CVE-2025-20129 [MEDIUM] CWE-200 GHSA-xpgj-x2hj-7mq2: A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthentic
A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data.
This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the chat interface of a targeted user on a vulnerable server. A successful exploit could allow the attacker to redirect chat traffic to a server that is under their control, resulting in sensitive information being redirected to the attacker.
Cisco
Cisco Customer Collaboration Platform Information Disclosure Vulnerability
vendor_cisco·2025-06-04·CVSS 4.3
CVE-2025-20129 [MEDIUM] CWE-200 Cisco Customer Collaboration Platform Information Disclosure Vulnerability
Cisco Customer Collaboration Platform Information Disclosure Vulnerability
A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data.
This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the chat interface of a targeted user on a vulnerable server. A successful exploit could allow the attacker to redirect chat traffic to a server that is under their control, resulting in sensitive information being redirected to the attacker.
Cisco has released software updates that address this vulnerabili
Cisco
Cisco Customer Collaboration Platform Information Disclosure Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20129 Cisco Customer Collaboration Platform Information Disclosure Vulnerability
CVE-2025-20129: Cisco Customer Collaboration Platform Information Disclosure Vulnerability
A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the chat interface of a targeted user on a vulnerable server. A successful exploit could allow the attacker to redirect chat traffic to a server that is under their control, resulting in sensitive information being redirected to the attacker. Cisco has released software updates that address thi
No detection rules found.
No public exploits indexed.
2025-06-04
Published