CVE-2019-19865
Summary
| CVE | CVE-2019-19865 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-21 16:15:00 UTC |
| Updated | 2020-02-28 20:15:00 UTC |
| Description | Atos Unify OpenScape UC Application V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows XSS. An attacker could exploit this by convincing an authenticated user to inject arbitrary JavaScript code in the Profile Name field. A browser would execute this stored XSS payload. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Atos | Unify Openscape Uc Web Client | 1.0 | All | All | All |
| Application | Atos | Unify Openscape Uc Web Client | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| networks.unify.com/security/advisories/OBSO-2002-01.pdf | MISC | networks.unify.com | Vendor Advisory |
| Security Advisories and Security Notes - Unify | MISC | unify.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.