ZeroHour

CVE-2024-52882

CVSS 3.1
6.1 medium
EPSS
<1%p14
Published
()
Modified
Description

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions.

Vendors
audiocodes
Products
one voice operations center
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.