packetstormsecurity.com
http://packetstormsecurity.com/files/156476/Avaya-IP-Office-Application-Server-11.0.0.0-Cross-Site-Scripting.html CVE-2019-7004
MEDIUM
Avaya IP Office XSS Vulnerability
Record summary
CVE-2019-7004 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit.
Description
A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potentially disclose sensitive information. All product versions 11.x are affected. Product versions prior to 11.0, including unsupported versions, were not evaluated.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
IP Office Application ServerBrowse Avaya / IP Office Application Server | CVE List | 11.x to ≤ 11.0 FP4 SP1 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBAvaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site ScriptingExploitDB exploitby Scott GoodwinNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-7004 support.avaya.comConfirmation
https://support.avaya.com/css/P8/documents/101062833