CVE-2018-15614
IP Office one-X Portal XSS
Severity Score
5.4
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via fields in the Conference Scheduler Service that could affect other application users. Affected versions of IP Office include 10.0 through 10.1 SP3 and 11.0 versions prior to 11.0 SP1.
Una vulnerabilidad en el componente one-x Portal de IP Office podría permitir que un usuario autenticado realice ataques de Cross-Site Scripting (XSS) persistente mediante cambios en el servicio "Conference Scheduler" que podrían afectar a otros usuarios de la aplicación. Las versiones afectadas de IP Office incluyen desde la 10.0 hasta la 10.1 SP3 y las versiones 11.0 anteriores a la 11.0 SP1.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2018-08-21 CVE Reserved
- 2019-01-23 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://downloads.avaya.com/css/P8/documents/101054317 | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Avaya Search vendor "Avaya" | Ip Office Search vendor "Avaya" for product "Ip Office" | 10.0 Search vendor "Avaya" for product "Ip Office" and version "10.0" | - |
Affected
| ||||||
Avaya Search vendor "Avaya" | Ip Office Search vendor "Avaya" for product "Ip Office" | 10.0 Search vendor "Avaya" for product "Ip Office" and version "10.0" | sp1 |
Affected
| ||||||
Avaya Search vendor "Avaya" | Ip Office Search vendor "Avaya" for product "Ip Office" | 10.0 Search vendor "Avaya" for product "Ip Office" and version "10.0" | sp2 |
Affected
| ||||||
Avaya Search vendor "Avaya" | Ip Office Search vendor "Avaya" for product "Ip Office" | 10.0 Search vendor "Avaya" for product "Ip Office" and version "10.0" | sp3 |
Affected
| ||||||
Avaya Search vendor "Avaya" | Ip Office Search vendor "Avaya" for product "Ip Office" | 10.0 Search vendor "Avaya" for product "Ip Office" and version "10.0" | sp4 |
Affected
| ||||||
Avaya Search vendor "Avaya" | Ip Office Search vendor "Avaya" for product "Ip Office" | 10.0 Search vendor "Avaya" for product "Ip Office" and version "10.0" | sp5 |
Affected
| ||||||
Avaya Search vendor "Avaya" | Ip Office Search vendor "Avaya" for product "Ip Office" | 10.0 Search vendor "Avaya" for product "Ip Office" and version "10.0" | sp6 |
Affected
| ||||||
Avaya Search vendor "Avaya" | Ip Office Search vendor "Avaya" for product "Ip Office" | 10.0 Search vendor "Avaya" for product "Ip Office" and version "10.0" | sp7 |
Affected
| ||||||
Avaya Search vendor "Avaya" | Ip Office Search vendor "Avaya" for product "Ip Office" | 10.1 Search vendor "Avaya" for product "Ip Office" and version "10.1" | - |
Affected
| ||||||
Avaya Search vendor "Avaya" | Ip Office Search vendor "Avaya" for product "Ip Office" | 10.1 Search vendor "Avaya" for product "Ip Office" and version "10.1" | sp1 |
Affected
| ||||||
Avaya Search vendor "Avaya" | Ip Office Search vendor "Avaya" for product "Ip Office" | 10.1 Search vendor "Avaya" for product "Ip Office" and version "10.1" | sp2 |
Affected
| ||||||
Avaya Search vendor "Avaya" | Ip Office Search vendor "Avaya" for product "Ip Office" | 10.1 Search vendor "Avaya" for product "Ip Office" and version "10.1" | sp3 |
Affected
| ||||||
Avaya Search vendor "Avaya" | Ip Office Search vendor "Avaya" for product "Ip Office" | 11.0 Search vendor "Avaya" for product "Ip Office" and version "11.0" | - |
Affected
|