Vulnerabilities (CVE)

Filtered by vendor Avaya Subscribe
Filtered by product Call Management System
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-3527 1 Avaya 1 Call Management System 2023-07-28 N/A 6.8 MEDIUM
A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted data which, when exported to a CSV file, may attempt arbitrary command execution on the system used to open the file by a spreadsheet software such as Microsoft Excel.