PT-2020-19349 · Avaya · Avaya Equinox Conferencing

Adrian Von Arx

·

Published

2020-11-12

·

Updated

2020-11-30

·

CVE-2020-7033

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Avaya Equinox Conferencing versions 9.x before 9.1.10
Description A Cross Site Scripting (XSS) vulnerability on the Unified Portal Client (web client) used in Avaya Equinox Conferencing can allow an authenticated user to perform XSS attacks.
Recommendations For versions 9.x before 9.1.10, update to version 9.1.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the Unified Portal Client (web client) until a patch is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7033

Affected Products

Avaya Equinox Conferencing