VYPR
Medium severity6.1NVD Advisory· Published Jul 31, 2019· Updated Jun 17, 2026

CVE-2019-7000

CVE-2019-7000

Description

A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potentially disclose sensitive information. Affected versions of Avaya Aura Conferencing include all 8.x versions prior to 8.0 SP14 (8.0.14). Prior versions not listed were not evaluated.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

13
  • cpe:2.3:a:avaya:aura_conferencing:*:*:*:*:*:*:*:*+ 12 more
    • cpe:2.3:a:avaya:aura_conferencing:*:*:*:*:*:*:*:*range: <=8.0
    • cpe:2.3:a:avaya:aura_conferencing:8.0:-:*:*:*:*:*:*
    • cpe:2.3:a:avaya:aura_conferencing:8.0:sp10:*:*:*:*:*:*
    • cpe:2.3:a:avaya:aura_conferencing:8.0:sp11:*:*:*:*:*:*
    • cpe:2.3:a:avaya:aura_conferencing:8.0:sp12:*:*:*:*:*:*
    • cpe:2.3:a:avaya:aura_conferencing:8.0:sp13:*:*:*:*:*:*
    • cpe:2.3:a:avaya:aura_conferencing:8.0:sp2:*:*:*:*:*:*
    • cpe:2.3:a:avaya:aura_conferencing:8.0:sp4:*:*:*:*:*:*
    • cpe:2.3:a:avaya:aura_conferencing:8.0:sp5:*:*:*:*:*:*
    • cpe:2.3:a:avaya:aura_conferencing:8.0:sp7:*:*:*:*:*:*
    • cpe:2.3:a:avaya:aura_conferencing:8.0:sp8:*:*:*:*:*:*
    • (no CPE)range: <8.0 SP14
    • (no CPE)range: 8.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.