← Back

CVE-2018-15614

nvd nist
Published: Jan 23, 2019Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via fields in the Conference Scheduler Service that could affect other application users. Affected versions of IP Office include 10.0 through 10.1 SP3 and 11.0 versions prior to 11.0 SP1.

Affected (13)

Products: Avaya: Ip Office
1 product
Ip Office
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Avaya
Version 10.0
Version 10.0 sp1
Version 10.0 sp2
Version 10.0 sp3
Version 10.0 sp4
Version 10.0 sp5
Version 10.0 sp6
Version 10.0 sp7
Version 10.1
Version 10.1 sp1
Version 10.1 sp2
Version 10.1 sp3
Version 11.0

References (2)

Source: securityalerts@avaya.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.