Vulnerability Name: | CVE-2021-25656 (CCN-204415) | ||||||||||||
Assigned: | 2021-06-15 | ||||||||||||
Published: | 2021-06-15 | ||||||||||||
Updated: | 2021-06-30 | ||||||||||||
Summary: | Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix). | ||||||||||||
CVSS v3 Severity: | 5.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
5.1 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:H/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-25656 Source: CCN Type: Avaya Security Advisory ASA-2021-069 Avaya Aura Experience Portal Vulnerabilities (CVE-2021-25655, CVE-2021-25656) Source: MISC Type: Patch, Vendor Advisory https://downloads.avaya.com/css/P8/documents/101076234 Source: XF Type: UNKNOWN avaya-cve202125656-xss(204415) | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |