CVE-2018-15614

A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via fields in the Conference Scheduler Service that could affect other application users. Affected versions of IP Office include 10.0 through 10.1 SP3 and 11.0 versions prior to 11.0 SP1.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
avayaCNA
6.8 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
VendorProductVersion
avayaip_office
10.0
avayaip_office
10.0:sp1
avayaip_office
10.0:sp2
avayaip_office
10.0:sp3
avayaip_office
10.0:sp4
avayaip_office
10.0:sp5
avayaip_office
10.0:sp6
avayaip_office
10.0:sp7
avayaip_office
10.1
avayaip_office
10.1:sp1
avayaip_office
10.1:sp2
avayaip_office
10.1:sp3
avayaip_office
11.0
𝑥
= Vulnerable software versions