A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2, 22.24.1500.0 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the test_presenter.php page. A successful exploit could allow an attacker to execute arbitrary scripts.
2023-05-24T21:15:11.380
2025-01-16T21:15:14.000
Modified
CVSSv3.1: 7.4 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mitel | mivoice_connect | < 19.3 | Yes |
Application | mitel | mivoice_connect | 19.3 | Yes |
Application | mitel | mivoice_connect | 19.3 | Yes |
Application | mitel | mivoice_connect | 19.3 | Yes |