Cross-Site Scripting Vulnerability in Avaya Spaces
CVE-2024-12755

5.4MEDIUM

Key Information:

Vendor

Avaya

Vendor
CVE Published:
11 February 2025

What is CVE-2024-12755?

A Cross-Site Scripting vulnerability in Avaya Spaces could potentially allow unauthorized users to execute malicious code within the application. This can lead to the disclosure of sensitive information, as attackers could manipulate the web environment to perform unauthorized actions that compromise user data and privacy. Proper validation and sanitization of user inputs are essential to mitigate this risk and protect against such vulnerabilities.

Affected Version(s)

Avaya Spaces 0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Waleed Elnawawy from Dubai Islamic Bank
Mostafa Noureldin from Liquid C2 Egypt
.
CVE-2024-12755 : Cross-Site Scripting Vulnerability in Avaya Spaces