CVE-2024-35283: XSS
A vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a stored cross-site scripting (XSS) attack due to insufficient input validation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35283?
CVE-2024-35283 has been assigned a high severity level due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2024-35283?
To fix CVE-2024-35283, update the Mitel MiContact Center Business to the latest version beyond 10.0.0.4, which addresses the input validation issue.
What are the consequences of exploiting CVE-2024-35283?
Exploiting CVE-2024-35283 could allow an attacker to execute arbitrary JavaScript in the context of a user's session, potentially stealing sensitive information.
Who is affected by CVE-2024-35283?
CVE-2024-35283 affects users running Mitel MiContact Center Business versions up to and including 10.0.0.4.
Is CVE-2024-35283 a remote vulnerability?
Yes, CVE-2024-35283 is a remote vulnerability that can be exploited by an unauthenticated attacker without physical access to the system.