Stored Cross-Site Scripting Vulnerability in Mitel Web Application
CVE-2026-104807
1.9LOW
What is CVE-2026-104807?
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the Mitel web application, enabling authenticated attackers to inject persistent JavaScript or HTML content. This issue arises within the web portal on TCP port 443, specifically in the 'Description' field under Configuration → Domains. The application inadequately validates or sanitizes user input, permitting attackers to manipulate the content viewed by other users. By executing this attack, malicious users can alter the appearance of pages, display harmful content, and create deceptive phishing scenarios that exploit the website's trusted environment.
Affected Version(s)
Mitel MiVoice Office 400 Linux 11.0.96.0