CVE-2020-24594: XSS
Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain access to a user session.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24594?
CVE-2020-24594 is a vulnerability that affects Mitel MiCloud Management Portal before 6.1 SP5 and could allow an unauthenticated attacker to execute arbitrary scripts.
What is the severity of CVE-2020-24594?
The severity of CVE-2020-24594 is rated as critical with a CVSS score of 9.6.
What is Mitel MiCloud Management Portal?
Mitel MiCloud Management Portal is a software used for managing MiCloud services.
How does CVE-2020-24594 work?
CVE-2020-24594 works by exploiting insufficient input validation, allowing an attacker to execute arbitrary scripts.
How can I mitigate the vulnerability in Mitel MiCloud Management Portal?
To mitigate the vulnerability in Mitel MiCloud Management Portal, make sure to update to version 6.1 SP5 or later.