Reflected Cross-Site Scripting Vulnerability in Mitel MiVoice Connect and ST Products
CVE-2018-9104
6.1MEDIUM
What is CVE-2018-9104?
A security flaw in the conferencing component of Mitel MiVoice Connect and ST products permits unauthenticated attackers to exploit an XSS vulnerability due to inadequate validation of input parameters in the api.php page. If successfully executed, this vulnerability could enable attackers to run arbitrary scripts within the context of the user. This could lead to unauthorized actions, data exposure, and potential manipulation of user sessions.