CVE-2020-7036: Avaya Callback Assist
Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.
An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Callback Assist includes all 4.0.x versions before 4.7.1.1 Patch 7.
Affected products
- Avaya Callback Assist: from 4.0.0, before 4.7.1.1 (fixed in 4.7.1.1); version 4.7.1.1 only
Published 2021-04-23. Last modified 2026-06-17.