PoC Index

CVE-2019-7004

MEDIUM 6.4EPSS 2.2%

A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potentially disclose sensitive information. All product versions 11.x are affected. Product versions prior to 11.0, including unsupported versions, were not evaluated.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v3.0
6.4 MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
2.18% chance of exploitation in the next 30 days, 81th percentile
Published
2019-12-11
Updated
2024-09-17

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related