Reflected Cross-Site Scripting Vulnerability in Mitel MiVoice Connect and ST Products
CVE-2018-9104
6.1MEDIUM
Summary
A security flaw in the conferencing component of Mitel MiVoice Connect and ST products permits unauthenticated attackers to exploit an XSS vulnerability due to inadequate validation of input parameters in the api.php page. If successfully executed, this vulnerability could enable attackers to run arbitrary scripts within the context of the user. This could lead to unauthorized actions, data exposure, and potential manipulation of user sessions.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved