CVE-2020-10211: Input Validation
A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to execute arbitrary scripts due to insufficient validation of URL parameters. A successful exploit could allow an attacker to gain access to sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10211?
CVE-2020-10211 is a remote code execution vulnerability in the UCB component of Mitel MiVoice Connect before version 19.1 SP1.
How does CVE-2020-10211 work?
CVE-2020-10211 allows an unauthenticated remote attacker to execute arbitrary scripts by exploiting insufficient validation of URL parameters.
What is the severity of CVE-2020-10211?
CVE-2020-10211 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2020-10211?
Mitel MiVoice Connect before version 19.1 SP1 and Mitel MiVoice Connect Client before version 214.100.1213.0 are affected by CVE-2020-10211.
How can I fix CVE-2020-10211?
To fix CVE-2020-10211, it is recommended to update to Mitel MiVoice Connect version 19.1 SP1 or later, and Mitel MiVoice Connect Client version 214.100.1213.0 or later.