Cross-Site Scripting Vulnerability in Avaya Spaces
CVE-2024-12755

7.9HIGH

Key Information:

Vendor
Avaya
Vendor
CVE Published:
11 February 2025

Summary

A Cross-Site Scripting vulnerability in Avaya Spaces could potentially allow unauthorized users to execute malicious code within the application. This can lead to the disclosure of sensitive information, as attackers could manipulate the web environment to perform unauthorized actions that compromise user data and privacy. Proper validation and sanitization of user inputs are essential to mitigate this risk and protect against such vulnerabilities.

Affected Version(s)

Avaya Spaces 0

References

CVSS V3.1

Score:
7.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Waleed Elnawawy from Dubai Islamic Bank
Mostafa Noureldin from Liquid C2 Egypt
.