CVE-2021-25656

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
24/06/2021
Last modified:
30/06/2021

Description

Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:avaya:aura_experience_portal:*:*:*:*:*:*:*:* 7.0 (including) 7.2.3 (including)
cpe:2.3:a:avaya:aura_experience_portal:8.0.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools