CVE-2024-52882

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:audiocodes:one_voice_operations_center:*:*:*:*:*:*:*:*

History

01 May 2025, 14:25

Type Values Removed Values Added
CPE cpe:2.3:a:audiocodes:one_voice_operations_center:*:*:*:*:*:*:*:*
First Time Audiocodes one Voice Operations Center
Audiocodes
References () https://www.audiocodes.com/solutions-products/products/management-products-solutions/one-voice-operations-center - () https://www.audiocodes.com/solutions-products/products/management-products-solutions/one-voice-operations-center - Product
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-076.txt - () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-076.txt - Third Party Advisory
Summary
  • (es) Se descubrió un problema en AudioCodes One Voice Operations Center (OVOC) anterior a la versión 8.4.582. Debido a la neutralización incorrecta de la entrada a través de la API de dispositivos, un atacante puede inyectar código JavaScript malicioso (XSS) para atacar las sesiones de administrador iniciadas.

10 Feb 2025, 17:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

07 Feb 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-07 16:15

Updated : 2025-05-01 14:25


NVD link : CVE-2024-52882

Mitre link : CVE-2024-52882

CVE.ORG link : CVE-2024-52882


JSON object : View

Products Affected

audiocodes

  • one_voice_operations_center
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')