[CIVN-2025-0275] Cross-Site Scripting Vulnerability in CISCO
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Cross-Site Scripting Vulnerability in CISCO
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: MEDIUM
Systems Affected
Cisco BroadWorks CommPilot Application Software
Overview
A vulnerability has been reported in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
Target Audience:
All IT administrators and individuals responsible for maintaining and updating in web-based management interface of Cisco BroadWorks CommPilot Application Software.
Risk Assessment:
High risk of data manipulation and service disruption.
Impact Assessment:
Potential impact on confidentiality, integrity, and availability of the system.
Description
This vulnerability exists due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface.
Successful exploitation of this vulnerability could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Solution
Apply appropriate updates as mentioned in Cisco Advisory
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-broadworks-xss-O696ymRA
Vendor Information
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-broadworks-xss-O696ymRA
References
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-broadworks-xss-O696ymRA
CVE Name
CVE-2025-20307
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmj56nAACgkQ3jCgcSdc
ys8XOw//aYnUVLrxbCXlIMS5oY549DYanGpcz0yI1QfZkxT+ODF2CfOBXsUzk3F9
csQ1yx1qvN5wA92ejjM3cPR2p1L4nEg/Y167vEX5vl1zOAfYEulHhQRAI7pjXFxF
wQATm4emM3/e9j+2PRSSewXHZLCPhnZfSo4Mn/lZZN9sKfMn0SRKe9PHXjB8GoRM
8cLRzCjSap/gXzr1Qw6wPdVHZwIeTzI9oBTWhivAMJpkOa6aA61R2ICEHAPnfRbS
13Nh1wTkKpVRFnjh42LPOvYHSM59zhTNfSniqXvcdoj22KdbGBarLHe2jvn6NA+i
Rz7qCd4jpXryfm/2842eJkWzNEb2A58r5B3ITrD57egTICmYOLavqDKkYaFEOQhl
OtFj+4LP+hXNMPAKlz3p6Ydkkm869mhoc2/qREyht3eWrVUsphyrYu1yxhfjlGG9
US3DuGsrm+T/IdxKf65mTB1gN63E1JW9te/ZAfo6g8VUywZqpT2O5U2M7AM/GNTY
cS+0A9CpzzdYbjm/mcLlehieg3Vh3Vw1D4GVrHKHElwx7ChFh5j5EzkTCFom7yLk
CLfnsOrz852eGEDtUuEFYd6JGNhseOLOO1Qz9PmrDfIKIf0YjnPOKzXAkDogvwDf
1hEA/89lX9e4XWYXrxYL0CPuNmlZA+V+sRvW+ioR2gAk7f3l/Ck=
=IYdz
—–END PGP SIGNATURE—–