CVE-2019-7004 EXPLOIT
5.4
MEDIUM · CVSS 3.1 · EPSS 2.2% (pctl 82)
Patch early
A public exploit exists.
Description
A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potentially disclose sensitive information. All product versions 11.x are affected. Product versions prior to 11.0, including unsupported versions, were not evaluated.
Scoring
| CVSS | 5.4 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 2.18% — more likely to be exploited than 82% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-12-12 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| avaya | ip office application server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Avaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site Scripting | 2020-02-24 |
References
- http://packetstormsecurity.com/files/156476/Avaya-IP-Office-Application-Server-11.0.0.0-Cross-Site-Scripting.html
- https://support.avaya.com/css/P8/documents/101062833
- http://packetstormsecurity.com/files/156476/Avaya-IP-Office-Application-Server-11.0.0.0-Cross-Site-Scripting.html
- https://support.avaya.com/css/P8/documents/101062833
→ the Explorer · watch your stack · NVD