First published: Sat Mar 16 2024(Updated: )
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation. A successful exploit could allow an attacker to access sensitive information and gain unauthorized access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel MiContact Center Business | <10.0.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28070 is classified as a medium-severity vulnerability due to its potential impact on sensitive information.
To mitigate CVE-2024-28070, ensure that input validation is properly implemented and consider updating to the latest version of Mitel MiContact Center Business.
CVE-2024-28070 allows for reflected cross-site scripting (XSS) attacks, enabling attackers to execute arbitrary scripts in users' browsers.
CVE-2024-28070 affects users of Mitel MiContact Center Business versions up to and including 10.0.0.4.
Yes, CVE-2024-28070 can be exploited remotely by an unauthenticated attacker due to insufficient input validation.