VYPR
Unrated severityNVD Advisory· Published Jan 23, 2019· Updated Aug 5, 2024

IP Office one-X Portal XSS

CVE-2018-15614

Description

A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via fields in the Conference Scheduler Service that could affect other application users. Affected versions of IP Office include 10.0 through 10.1 SP3 and 11.0 versions prior to 11.0 SP1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Avaya/IP Officellm-fuzzy2 versions
    >=10.0 <=10.1 SP3, <11.0 SP1+ 1 more
    • (no CPE)range: >=10.0 <=10.1 SP3, <11.0 SP1
    • (no CPE)range: 11.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.