CVE-2024-28070: XSS
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation. A successful exploit could allow an attacker to access sensitive information and gain unauthorized access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28070?
CVE-2024-28070 is classified as a medium-severity vulnerability due to its potential impact on sensitive information.
How do I fix CVE-2024-28070?
To mitigate CVE-2024-28070, ensure that input validation is properly implemented and consider updating to the latest version of Mitel MiContact Center Business.
What types of attacks are possible with CVE-2024-28070?
CVE-2024-28070 allows for reflected cross-site scripting (XSS) attacks, enabling attackers to execute arbitrary scripts in users' browsers.
Who is affected by CVE-2024-28070?
CVE-2024-28070 affects users of Mitel MiContact Center Business versions up to and including 10.0.0.4.
Can CVE-2024-28070 be exploited remotely?
Yes, CVE-2024-28070 can be exploited remotely by an unauthenticated attacker due to insufficient input validation.