Mitel MiContact Center Business Vulnerability: Reflected XSS Attack Due to Input Validation Failure
CVE-2024-35284

5.4MEDIUM

Key Information:

Vendor

Mitel

Vendor
CVE Published:
29 May 2024

What is CVE-2024-35284?

The legacy chat component of Mitel MiContact Center Business versions up to 10.0.0.4 is susceptible to a reflected cross-site scripting attack. This vulnerability arises from insufficient input validation, allowing an unauthenticated attacker to potentially execute arbitrary JavaScript code in the context of a user's session. Attackers can exploit this weakness to manipulate web sessions, such as capturing sensitive user credentials or spreading malware. It is crucial for organizations utilizing this product to review security configurations and apply necessary updates from Mitel to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.