CVE-2025-20218 | Cisco Firepower Management Center up to 7.4.2.1 Web-based Management Interface xpath injection (cisco-sa-fmc-xpathinj-COrThdMb)
A vulnerability was found in Cisco Firepower Management Center and classified as problematic. Affected by this issue is some unknown functionality of the component Web-based Management Interface. The manipulation leads to improper neutralization of data within xpath expressions.
This vulnerability is handled as CVE-2025-20218. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.