Stored XSS Vulnerability in DigitalCanion's Web Portal for Mitel Users
CVE-2026-104808
1.9LOW
What is CVE-2026-104808?
DigitalCanion has identified a vulnerability in Mitel's web portal that allows authenticated users to exploit a failure in input validation within the 'Microsoft Exchange mailbox' field. This flaw enables users to inject persistent JavaScript or HTML content, leading to a denial-of-service condition. The vulnerability exists because user-supplied input is not properly sanitized before storage and rendering. Consequently, malicious scripts can execute when accessing the affected user properties, disrupting the application's user-management capabilities.
Affected Version(s)
Mitel MiVoice Office 400 Linux 11.0.96.0