CVE-2022-20802 describes a cross-site scripting (XSS) vulnerability in the web interface of Cisco Enterprise Chat and Email (ECE) due to insufficient input validation. An authenticated, remote attacker could exploit this by sending a crafted HTTP request. The vulnerability has a CVSS score of 5.4 (Medium), requiring valid agent credentials and user interaction, and could lead to arbitrary code execution or access to sensitive browser-based information. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.6\(1\)es2CPE matchmatch criteria | cpe:2.3:a:cisco:enterprise_chat_and_email:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.