Record summary

CVE-2019-7004 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit.

Description

A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potentially disclose sensitive information. All product versions 11.x are affected. Product versions prior to 11.0, including unsupported versions, were not evaluated.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List11.x to ≤ 11.0 FP4 SP1affected

Proofs of concept

1

Catalogued exploits

ExploitDBAvaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site ScriptingExploitDB exploitby Scott GoodwinNot analyzed1 file
ExploitDB

PoC details

References

3