peter bassill · operator
$ cve CVE-2019-7004 JSON

CVE-2019-7004 EXPLOIT

5.4
MEDIUM · CVSS 3.1 · EPSS 2.2% (pctl 82)

Patch early

A public exploit exists.

Description

A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potentially disclose sensitive information. All product versions 11.x are affected. Product versions prior to 11.0, including unsupported versions, were not evaluated.

Scoring

CVSS5.4 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS2.18% — more likely to be exploited than 82% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2019-12-12
Last modified2026-06-17

Affected (1)

VendorProduct
avayaip office application server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD