CVE-2018-9103: XSS
A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the signin.php page. A successful exploit could allow an attacker to execute arbitrary scripts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mitel MiVoice Connect (conferencing component)to a version that resolves this vulnerability.Fixed in R1707-PREM SP1 (21.84.5535.0) - Upgrade
Upgrade
Mitel ST 14.2to a version that resolves this vulnerability.Fixed in GA27 (19.49.5200.0) - Configuration
Fix the reflected XSS condition by ensuring signin.php performs sufficient validation for unauthenticated reflected XSS inputs.
signin.php (Mit el conferencing component) input validation for signin.php = validated
Event History
Frequently Asked Questions
What is CVE-2018-9103?
CVE-2018-9103 is a vulnerability in the conferencing component of Mitel MiVoice Connect and Mitel ST 14.2 that could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack.
How severe is CVE-2018-9103?
CVE-2018-9103 has a severity rating of 6.1, which is considered medium.
How can an attacker exploit CVE-2018-9103?
An attacker can exploit CVE-2018-9103 by conducting a reflected cross-site scripting (XSS) attack.
Which versions of Mitel MiVoice Connect are affected?
Mitel MiVoice Connect versions R1707-PREM SP1 (21.84.5535.0) and earlier are affected.
Which versions of Mitel ST 14.2 are affected?
Mitel ST 14.2 versions GA27 (19.49.5200.0) and earlier are affected.
How can I fix CVE-2018-9103?
To fix CVE-2018-9103, update to a version of Mitel MiVoice Connect or Mitel ST 14.2 that is later than the affected versions.