PT-2021-16733 · Avaya · Avaya Aura Experience Portal Web Management
Hieu Tran
·
Published
2021-06-24
·
Updated
2021-06-30
·
CVE-2021-25656
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Avaya Aura Experience Portal Web management versions 7.0 through 7.2.3
Avaya Aura Experience Portal Web management version 8.0.0
Description
Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management, which could allow an authenticated user to potentially disclose sensitive information.
Recommendations
For Avaya Aura Experience Portal Web management versions 7.0 through 7.2.3, apply the necessary hotfix to resolve the issue.
For Avaya Aura Experience Portal Web management version 8.0.0, apply the necessary hotfix to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avaya Aura Experience Portal Web Management