CVE-2024-52882

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:audiocodes:one_voice_operations_center:*:*:*:*:*:*:*:*

History

01 May 2025, 14:25

Type Values Removed Values Added
First Time Audiocodes
Audiocodes one Voice Operations Center
References () https://www.audiocodes.com/solutions-products/products/management-products-solutions/one-voice-operations-center - () https://www.audiocodes.com/solutions-products/products/management-products-solutions/one-voice-operations-center - Product
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-076.txt - () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-076.txt - Third Party Advisory
CPE cpe:2.3:a:audiocodes:one_voice_operations_center:*:*:*:*:*:*:*:*
Summary
  • (es) Se descubrió un problema en AudioCodes One Voice Operations Center (OVOC) anterior a la versión 8.4.582. Debido a la neutralización incorrecta de la entrada a través de la API de dispositivos, un atacante puede inyectar código JavaScript malicioso (XSS) para atacar las sesiones de administrador iniciadas.

10 Feb 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79

07 Feb 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-07 16:15

Updated : 2025-05-01 14:25


NVD link : CVE-2024-52882

Mitre link : CVE-2024-52882

CVE.ORG link : CVE-2024-52882


JSON object : View

Products Affected

audiocodes

  • one_voice_operations_center
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')