← Back

CVE-2021-25656

nvd nist
Published: Jun 24, 2021Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).

Affected (2)

1 product
Aura Experience Portal
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Avaya
From 7.0 to 7.2.3
Version 8.0.0

References (2)

Source: securityalerts@avaya.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.