CVE-2024-12756

HIGH

Avaya Spaces - Info Disclosure

Title source: llm
STIX 2.1

Description

An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of the page content seen by the user.

Scores

CVSS v3 7.3
EPSS 0.0005
EPSS Percentile 15.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1287 CWE-79
Status published
Products (1)
avaya/spaces
Published Feb 11, 2025
Tracked Since Feb 18, 2026