CVE-2025-20279 | Cisco Unified Contact Center Express up to 12.5(1)_SU03_ES06 Web-based Management Interface cross site scripting (cisco-sa-uccx-multi-UhOTvPGL / EUVD-2025-16885)
A vulnerability, which was classified as problematic, was found in Cisco Unified Contact Center Express. Affected is an unknown function of the component Web-based Management Interface. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-20279. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.