CVE-2020-28351: XSS
The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack (via the PATHINFO to index.php) due to insufficient validation for the timezone object in the HOMEMEETING& page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-28351?
CVE-2020-28351 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2020-28351?
To fix CVE-2020-28351, you should apply the latest firmware updates from Mitel for affected ShoreTel devices.
Who is affected by CVE-2020-28351?
CVE-2020-28351 affects users of Mitel ShoreTel firmware version 19.46.1802.0.
What type of attack can exploit CVE-2020-28351?
CVE-2020-28351 can be exploited via a reflected cross-site scripting (XSS) attack.
What is the primary cause of CVE-2020-28351?
The primary cause of CVE-2020-28351 is insufficient validation of the time_zone object in the HOME_MEETING& page.