First published: Thu May 07 2020(Updated: )
A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 allows remote attackers to inject arbitrary JavaScript and HTML via the PATH_INFO to home.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel MiVoice Connect | <21.90.9743.0 | |
Mitel ShoreTel Conference Web | =19.50.1000.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12679 is a reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application.
The severity of CVE-2020-12679 is medium with a CVSS score of 6.1.
CVE-2020-12679 impacts Mitel MiVoice Connect versions up to 21.90.9743.0.
CVE-2020-12679 impacts Mitel ShoreTel Conference Web version 19.50.1000.0.
Update Mitel ShoreTel Conference Web Application and Mitel MiVoice Connect to the latest secure versions.