CVE-2025-20180
Cisco Secure Email and Web Manager and Secure Email Gateway Cross-Site Scripting Vulnerability
Description
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Operator.
Weakness: CWE-79
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Secure Email Gateway | Email Security | cna-assigner |
Vendor-reported products (2)
- Cisco · Cisco Secure Email
- Cisco · Cisco Secure Email and Web Manager
Vendor advisory
Cisco Secure Email and Web Manager and Secure Email Gateway Cross-Site Scripting Vulnerability
Cisco’s rating: Medium (advisory CVSS 4.8) · Published Feb 5, 2025
Bug IDs: CSCwn25954 , CSCwn26371
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from