Code Execution Vulnerability in Mitel Connect ONSITE Conference Component
CVE-2018-5779

9.8CRITICAL

Key Information:

Vendor

Mitel

Vendor
CVE Published:
14 March 2018

What is CVE-2018-5779?

A serious security flaw exists within the conferencing component of Mitel Connect ONSITE and Mitel ST, which could allow an unauthenticated attacker to inject malicious scripts into newly created PHP files. By crafting specific requests, the attacker could execute arbitrary code, compromising the integrity of the application. This vulnerability emphasizes the need for strict access controls and regular security updates to protect against unauthorized scripting activities.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.