Mitel MiContact Center Business Vulnerability: Reflected XSS Attack Due to Input Validation Failure
CVE-2024-35284

Currently unrated

Key Information:

Vendor
Mitel
Vendor
CVE Published:
29 May 2024

Summary

The legacy chat component of Mitel MiContact Center Business versions up to 10.0.0.4 is susceptible to a reflected cross-site scripting attack. This vulnerability arises from insufficient input validation, allowing an unauthenticated attacker to potentially execute arbitrary JavaScript code in the context of a user's session. Attackers can exploit this weakness to manipulate web sessions, such as capturing sensitive user credentials or spreading malware. It is crucial for organizations utilizing this product to review security configurations and apply necessary updates from Mitel to mitigate the risks associated with this vulnerability.

References

Timeline

  • Vulnerability published

.