CVE-2018-16226: XSS
A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack, due to insufficient validation for the start.asp page. A successful exploit could allow the attacker to execute arbitrary scripts to access sensitive browser-based information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-16226?
CVE-2018-16226 is a vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, that could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack.
How severe is CVE-2018-16226?
CVE-2018-16226 has a severity rating of 6.1, which is considered medium.
How does CVE-2018-16226 affect Mitel MiVoice Office 400?
CVE-2018-16226 affects Mitel MiVoice Office 400 versions R5.0 HF3 (v8839a1) and earlier.
What is the impact of CVE-2018-16226?
The impact of CVE-2018-16226 is that an unauthenticated attacker could conduct a reflected cross-site scripting (XSS) attack.
Is there a fix for CVE-2018-16226?
Yes, Mitel has released a hotfix to address the vulnerability. Please refer to the Mitel Product Security Advisory 18-0008 for more information.