CVE-2025-20129
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
04/06/2025
Last modified:
01/08/2025
Description
A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data.<br />
<br />
This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the chat interface of a targeted user on a vulnerable server. A successful exploit could allow the attacker to redirect chat traffic to a server that is under their control, resulting in sensitive information being redirected to the attacker.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cisco:socialminer:10.5\(1\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:socialminer:10.6\(1\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:socialminer:10.6\(2\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:socialminer:11.0\(1\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:socialminer:11.5\(1\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:socialminer:11.5\(1\)su1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:socialminer:11.6\(1\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:socialminer:11.6\(2\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:socialminer:12.0\(1\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:socialminer:12.0\(1\)es02:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:socialminer:12.0\(1\)es03:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:socialminer:12.0\(1\)es04:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:socialminer:12.5\(1\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:socialminer:12.5\(1\)es01:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:socialminer:12.5\(1\)su1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



