CVE-2021-3176: Input Validation
The chat window of the Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.15 and 7.x before 7.1.2 could allow an attacker to gain access to user information by sending certain code, due to improper input validation of http links. A successful exploit could allow an attacker to view user information and application data.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-3176.
What software is affected by this vulnerability?
The Mitel BusinessCTI Enterprise (MBC-E) Client for Windows versions before 6.4.15 and 7.x before 7.1.2 are affected.
What is the severity of CVE-2021-3176?
The severity of CVE-2021-3176 is high with a CVSS score of 8.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by sending certain code through the chat window of the Mitel BusinessCTI Enterprise (MBC-E) Client for Windows.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability in the Mitel security advisories located at [https://www.mitel.com/support/security-advisories](https://www.mitel.com/support/security-advisories) and [https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-21-0001](https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-21-0001).