CVE-2019-7000

A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potentially disclose sensitive information. Affected versions of Avaya Aura Conferencing include all 8.x versions prior to 8.0 SP14 (8.0.14). Prior versions not listed were not evaluated.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
avayaCNA
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
avayaaura_conferencing
𝑥
≤ 8.0
avayaaura_conferencing
8.0
avayaaura_conferencing
8.0:sp10
avayaaura_conferencing
8.0:sp11
avayaaura_conferencing
8.0:sp12
avayaaura_conferencing
8.0:sp13
avayaaura_conferencing
8.0:sp2
avayaaura_conferencing
8.0:sp4
avayaaura_conferencing
8.0:sp5
avayaaura_conferencing
8.0:sp7
avayaaura_conferencing
8.0:sp8
𝑥
= Vulnerable software versions