CVE-2022-20631
A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious script code in a chat window. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
EPSS 0.51% · 41.5th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Enterprise Chat and Email | 11.6(1)_ES3, 11.6(1)_ES4, 12.0(1)_ES6 |
| cisco | enterprise_chat_and_email | 0 |
Timeline
- Nov 15, 2024 CVE Published
- Nov 15, 2024 CVE Updated
- Nov 16, 2024 EPSS Score
- Dec 5, 2024 EPSS Score
- Dec 23, 2024 EPSS Score
- Jan 9, 2025 EPSS Score
- Jan 27, 2025 EPSS Score
- Feb 14, 2025 EPSS Score
- Mar 4, 2025 EPSS Score
- Mar 21, 2025 EPSS Score
- Apr 8, 2025 EPSS Score
- Apr 26, 2025 EPSS Score