Medium severity6.8NVD Advisory· Published Jan 23, 2019· Updated Jun 17, 2026
CVE-2018-15614
CVE-2018-15614
Description
A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via fields in the Conference Scheduler Service that could affect other application users. Affected versions of IP Office include 10.0 through 10.1 SP3 and 11.0 versions prior to 11.0 SP1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1611.x+ 13 more
- (no CPE)range: 11.x
- cpe:2.3:a:avaya:ip_office:10.0:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office:10.0:sp1:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office:10.0:sp2:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office:10.0:sp3:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office:10.0:sp4:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office:10.0:sp5:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office:10.0:sp6:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office:10.0:sp7:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office:10.1:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office:10.1:sp1:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office:10.1:sp2:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office:10.1:sp3:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office:11.0:*:*:*:*:*:*:*
- Range: 10.0 through 10.1 SP3, 11.0 prior to 11.0 SP1
Patches
Vulnerability mechanics
References
1- downloads.avaya.com/css/P8/documents/101054317nvdVendor Advisory
News mentions
0No linked articles in our index yet.