CVE-2024-12756

HIGH

Avaya Spaces - HTML Injection

Title source: llm
STIX 2.1

Description

An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of the page content seen by the user.

References (1)

Core 1

Scores

CVSS v3 7.3
EPSS 0.0026
EPSS Percentile 17.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1287 CWE-79
Status published
Products (1)
avaya/spaces
Published Feb 11, 2025
Tracked Since Feb 18, 2026