Mitel MiContact Center Business Vulnerability: Reflected XSS Attack Due to Input Validation Failure
CVE-2024-35284
Currently unrated
Summary
The legacy chat component of Mitel MiContact Center Business versions up to 10.0.0.4 is susceptible to a reflected cross-site scripting attack. This vulnerability arises from insufficient input validation, allowing an unauthenticated attacker to potentially execute arbitrary JavaScript code in the context of a user's session. Attackers can exploit this weakness to manipulate web sessions, such as capturing sensitive user credentials or spreading malware. It is crucial for organizations utilizing this product to review security configurations and apply necessary updates from Mitel to mitigate the risks associated with this vulnerability.
References
Timeline
Vulnerability published