Medium severity5.4NVD Advisory· Published Dec 12, 2019· Updated Jun 17, 2026
CVE-2019-7004
CVE-2019-7004
Description
A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potentially disclose sensitive information. All product versions 11.x are affected. Product versions prior to 11.0, including unsupported versions, were not evaluated.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:avaya:ip_office_application_server:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:avaya:ip_office_application_server:*:*:*:*:*:*:*:*range: >=11.0,<=11.0.4.0
- (no CPE)range: 11.x
- (no CPE)range: 11.x
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/156476/Avaya-IP-Office-Application-Server-11.0.0.0-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- support.avaya.com/css/P8/documents/101062833nvdVendor Advisory
News mentions
0No linked articles in our index yet.