VYPR
Medium severity6.8NVD Advisory· Published Jan 23, 2019· Updated Jun 17, 2026

CVE-2018-15614

CVE-2018-15614

Description

A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via fields in the Conference Scheduler Service that could affect other application users. Affected versions of IP Office include 10.0 through 10.1 SP3 and 11.0 versions prior to 11.0 SP1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

16
  • Avaya/IP Officecpe-rescue14 versions
    11.x+ 13 more
    • (no CPE)range: 11.x
    • cpe:2.3:a:avaya:ip_office:10.0:*:*:*:*:*:*:*
    • cpe:2.3:a:avaya:ip_office:10.0:sp1:*:*:*:*:*:*
    • cpe:2.3:a:avaya:ip_office:10.0:sp2:*:*:*:*:*:*
    • cpe:2.3:a:avaya:ip_office:10.0:sp3:*:*:*:*:*:*
    • cpe:2.3:a:avaya:ip_office:10.0:sp4:*:*:*:*:*:*
    • cpe:2.3:a:avaya:ip_office:10.0:sp5:*:*:*:*:*:*
    • cpe:2.3:a:avaya:ip_office:10.0:sp6:*:*:*:*:*:*
    • cpe:2.3:a:avaya:ip_office:10.0:sp7:*:*:*:*:*:*
    • cpe:2.3:a:avaya:ip_office:10.1:*:*:*:*:*:*:*
    • cpe:2.3:a:avaya:ip_office:10.1:sp1:*:*:*:*:*:*
    • cpe:2.3:a:avaya:ip_office:10.1:sp2:*:*:*:*:*:*
    • cpe:2.3:a:avaya:ip_office:10.1:sp3:*:*:*:*:*:*
    • cpe:2.3:a:avaya:ip_office:11.0:*:*:*:*:*:*:*
  • Range: 10.0 through 10.1 SP3, 11.0 prior to 11.0 SP1
  • Range: 10.0 through 10.1 SP3, 11.0 prior to 11.0 SP1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.