CVE-2019-7000: Avaya Aura Conferencing

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potentially disclose sensitive information. Affected versions of Avaya Aura Conferencing include all 8.x versions prior to 8.0 SP14 (8.0.14). Prior versions not listed were not evaluated.

Affected products

  • Avaya Aura Conferencing: up to and including 8.0; version 8.0 only

Published 2019-07-31. Last modified 2026-06-17.