Code Execution Vulnerability in Mitel Connect ONSITE Conference Component
CVE-2018-5779
9.8CRITICAL
What is CVE-2018-5779?
A serious security flaw exists within the conferencing component of Mitel Connect ONSITE and Mitel ST, which could allow an unauthenticated attacker to inject malicious scripts into newly created PHP files. By crafting specific requests, the attacker could execute arbitrary code, compromising the integrity of the application. This vulnerability emphasizes the need for strict access controls and regular security updates to protect against unauthorized scripting activities.