PT-2020-19349 · Avaya · Avaya Equinox Conferencing
Adrian Von Arx
·
Published
2020-11-12
·
Updated
2020-11-30
·
CVE-2020-7033
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Avaya Equinox Conferencing versions 9.x before 9.1.10
Description
A Cross Site Scripting (XSS) vulnerability on the Unified Portal Client (web client) used in Avaya Equinox Conferencing can allow an authenticated user to perform XSS attacks.
Recommendations
For versions 9.x before 9.1.10, update to version 9.1.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the Unified Portal Client (web client) until a patch is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avaya Equinox Conferencing