Vulnerabilities (CVE)

Filtered by vendor Avaya Subscribe
Filtered by product Aura Experience Portal
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-25655 1 Avaya 1 Aura Experience Portal 2021-06-30 5.8 MEDIUM 6.1 MEDIUM
A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).
CVE-2021-25656 1 Avaya 1 Aura Experience Portal 2021-06-30 3.5 LOW 5.4 MEDIUM
Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).