An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions.
References
Configurations
History
01 May 2025, 14:25
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:audiocodes:one_voice_operations_center:*:*:*:*:*:*:*:* | |
First Time |
Audiocodes one Voice Operations Center
Audiocodes |
|
References | () https://www.audiocodes.com/solutions-products/products/management-products-solutions/one-voice-operations-center - Product | |
References | () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-076.txt - Third Party Advisory | |
Summary |
|
10 Feb 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
07 Feb 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-07 16:15
Updated : 2025-05-01 14:25
NVD link : CVE-2024-52882
Mitre link : CVE-2024-52882
CVE.ORG link : CVE-2024-52882
JSON object : View
Products Affected
audiocodes
- one_voice_operations_center
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')