CVE-2025-20216

A vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to inject HTML into the browser of an authenticated user. This vulnerability is due to improper sanitization of input to the web interface. An attacker could exploit this vulnerability by convincing an authenticated user to click a malicious link. A successful exploit could allow the attacker to inject HTML into the browser of an authenticated Cisco Catalyst SD-WAN Manager user.
Configurations

No configuration.

History

08 May 2025, 14:39

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad en la interfaz web de Cisco Catalyst SD-WAN Manager, anteriormente Cisco SD-WAN vManage, podría permitir que un atacante remoto no autenticado inyecte HTML en el navegador de un usuario autenticado. Esta vulnerabilidad se debe a una limpieza inadecuada de la entrada a la interfaz web. Un atacante podría explotar esta vulnerabilidad convenciendo a un usuario autenticado de hacer clic en un enlace malicioso. Una explotación exitosa podría permitir al atacante inyecte HTML en el navegador de un usuario autenticado de Cisco Catalyst SD-WAN Manager.

07 May 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-07 18:15

Updated : 2025-05-08 14:39


NVD link : CVE-2025-20216

Mitre link : CVE-2025-20216

CVE.ORG link : CVE-2025-20216


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')