Cisco Enterprise Chat and Email Stored Cross-Site Scripting Vulnerability

🚨 SEVERITY: MEDIUM β€” CVSS 6.1 Security Advisory

TL;DR πŸ“Œ

  • A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web UI does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to…
  • No fixed release listed yet; apply mitigations and monitor.
  • Workarounds are documented in the advisory.
  • CVEs: CVE-2025-20310.

What happened πŸ•΅οΈβ€β™‚οΈ

A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.

This vulnerability exists because the web UI does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To successfully exploit this vulnerability, an attacker would need valid agent credentials.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. There is a mitigation that addresses this vulnerability.

Affected products πŸ–₯️

At the time of publication, this vulnerability affected Cisco ECE if it had the inbound email security policy of the rich text content policy disabled.

For information about which Cisco software releases were vulnerable at the time of publication, see the Fixed Software ["#fs"] section of this advisory. See the Details section in the bug ID(s) at the top of this advisory for the most complete and current information.

Determine the Rich Text Content Policy Configuration

To determine the status of the inbound email security policy setting of the Cisco ECE server rich text content policy, connect to the ECE System Console or Cisco Packaged Contact Center Enterprise (PCCE) Single Pane of Glass (SPOG), and choose Digital Channels > Chat and Email > Partition > Security > Rich Text Content Policy.

If the inbound email security policy setting is enabled, the system is not affected by this vulnerability. If the setting is disabled, the system is affected by this vulnerability.

Fixed software πŸ”§

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
11 Migrate to a fixed release.
12 12.6(1)_ES11
15 Not vulnerable.
1.0 Initial public release.

Workarounds 🧯

There are no workarounds that address this vulnerability. However, enabling the inbound email security policy setting of the Cisco ECE server rich text content policy mitigates this vulnerability.

To enable this setting, connect to the UCCE System Console and choose Digital Channels > Chat and Email > Partition > Security > Rich Text Content Policy. Change the inbound email security policy setting to enabled.

While this mitigation has been deployed and was proven successful in a test environment, customers should determine the applicability and effectiveness in their own environment and under their own use conditions. Customers should be aware that any workaround or mitigation that is implemented may negatively impact the functionality or performance of their network based on intrinsic customer deployment scenarios and limitations. Customers should not deploy any workarounds or mitigations before first evaluating the applicability to their own environment and any impact to such environment.

Risk in context 🎯

Use vendor CVSS for prioritization. Consider exposure and asset criticality.

Fast facts ⚑

  • Advisory: cisco-sa-ece-xss-CbtKtEYc
  • Initial release: 2025-07-02T16:00:00 UTC
  • Last updated: 2025-07-02T16:00:00 UTC

For leadership 🧭

Executive summary. Cisco ECE agents could have malicious script executed in their browser session if the platform’s inbound email rich text content policy is switched off, exposing session data to an attacker who already holds valid agent credentials. There’s no fixed release listed yet, so this needs a configuration check and mitigation applied in the next change window rather than waiting for a patch.

Why it matters:

  • The flaw sits in the ECE web UI used by chat and email agents, meaning a successful exploit runs script inside the agent’s active session, not a public-facing page.
  • Exploitation requires an attacker to already hold valid agent credentials and to persuade a user to click a crafted link, so it’s a risk amplifier for compromised or malicious insider accounts rather than an anonymous internet attack.
  • Affected systems are specifically those with the inbound email security policy’s rich text content policy disabled β€” leaving this default-off setting unchecked directly determines exposure.
  • No workaround exists, and no fixed software release is currently listed, so the only available defence is the configuration mitigation until Cisco ships a fix.

Now / Next / Later:

  • Now: Check the Rich Text Content Policy setting via the ECE System Console or PCCE SPOG (Digital Channels > Chat and Email > Partition > Security) to confirm whether inbound email security policy is enabled or disabled.
  • Next: If disabled, enable the inbound email security policy setting as the documented mitigation, testing first for any impact on rich text email handling in your environment.
  • Later: Track Cisco’s fixed software releases for ECE and schedule an upgrade once a fix is published, and add rich text/input validation policy checks to routine ECE configuration audits.