CVE-2023-25598: XSS
Published May 24, 2023
·Updated
A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2 and 20.x, 21.x, and 22.x through 22.24.1500.0 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the home.php page. A successful exploit could allow an attacker to execute arbitrary scripts.
Affected Software
1 affected component
Mitel MiVoice Connect<=22.24.1500.0
Event History
May 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-25598.
2
What is the severity level of CVE-2023-25598?
The severity level of CVE-2023-25598 is medium.
3
What software versions are affected by this vulnerability?
Mitel MiVoice Connect versions up to and including 22.24.1500.0 are affected by this vulnerability.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-79.
5
What is the risk of this vulnerability?
This vulnerability could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack.