Reflected XSS Vulnerability in ShoreTel Connect by ShoreTel
CVE-2019-9591
6.1MEDIUM
What is CVE-2019-9591?
A reflected XSS vulnerability exists in ShoreTel Connect ONSITE versions prior to 19.49.1500.0, enabling remote attackers to inject arbitrary web scripts or HTML code through the 'brandUrl' parameter. This can potentially lead to unauthorized actions being performed on behalf of the victim, making it imperative for users to apply security updates to mitigate these risks.