Reflected Cross-Site Scripting Vulnerability in Mitel MiVoice Connect and ST Products
CVE-2018-9104

6.1MEDIUM

Key Information:

Vendor
Mitel
Vendor
CVE Published:
25 April 2018

Summary

A security flaw in the conferencing component of Mitel MiVoice Connect and ST products permits unauthenticated attackers to exploit an XSS vulnerability due to inadequate validation of input parameters in the api.php page. If successfully executed, this vulnerability could enable attackers to run arbitrary scripts within the context of the user. This could lead to unauthorized actions, data exposure, and potential manipulation of user sessions.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.