First published: Wed Mar 06 2019(Updated: )
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel Connect | =19.45.1602.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9592 is classified as a medium severity vulnerability due to its potential impact on user data integrity.
To fix CVE-2019-9592, update ShoreTel Connect ONSITE to the latest version that addresses this reflected XSS vulnerability.
CVE-2019-9592 affects the ShoreTel Connect ONSITE version 19.45.1602.0 and allows for remote script injection.
Yes, CVE-2019-9592 can be exploited remotely by attackers injecting malicious scripts through the url parameter.
The main risks associated with CVE-2019-9592 include unauthorized access to user sessions and potential data theft.