VulnerabilityModified
CVE-2019-19865
Atos Unify OpenScape UC Application V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows XSS.
MEDIUM 6.1EPSS 0.65%
Does this matter?
Lower severity and a low EPSS score (0.65%). Track it; it rarely justifies an emergency change on its own.
Description
Atos Unify OpenScape UC Application V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows XSS. An attacker could exploit this by convincing an authenticated user to inject arbitrary JavaScript code in the Profile Name field. A browser would execute this stored XSS payload.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.65% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- atos/unify openscape uc web client
- Source
- cve@mitre.org
References
- https://networks.unify.com/security/advisories/OBSO-2002-01.pdfVendor Advisory
- https://unify.com/en/support/security-advisoriesVendor Advisory
- https://networks.unify.com/security/advisories/OBSO-2002-01.pdfVendor Advisory
- https://unify.com/en/support/security-advisoriesVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.