1 results (0.007 seconds)

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 0

A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the signin.php page. A successful exploit could allow an attacker to execute arbitrary scripts. Una vulnerabilidad en el componente conferencing de Mitel ST 14.2, en versiones GA29 (19.49.9400.0) y anteriores, podría permitir que un atacante no autenticado lleve a cabo un ataque Cross-Site Scripting (XSS) reflejado debido a la validación insuficiente de la página signin.php. Su explotación con éxito podría permitir que el atacante ejecute scripts arbitrarios. • https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0007 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •