Cross-Site Scripting Vulnerability in Atos Unify OpenScape UC Application
CVE-2019-19865

6.1MEDIUM

Key Information:

Vendor

Atos

Vendor
CVE Published:
21 February 2020

What is CVE-2019-19865?

The Atos Unify OpenScape UC Application is susceptible to cross-site scripting (XSS) vulnerabilities that allow attackers to exploit the Profile Name field. By persuading an authenticated user to enter malicious JavaScript, attackers can store this payload, leading to potential unauthorized actions from the user's session. Ensure your application is updated to mitigate these risks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.