CVE-2024-35284: XSS
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35284?
CVE-2024-35284 is classified as a high severity vulnerability due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2024-35284?
To remediate CVE-2024-35284, it is recommended to update Mitel MiContact Center Business to the latest version beyond 10.0.0.4 that addresses the vulnerability.
Who is affected by CVE-2024-35284?
CVE-2024-35284 affects users of Mitel MiContact Center Business versions up to and including 10.0.0.4.
What type of attack does CVE-2024-35284 allow?
CVE-2024-35284 allows an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack.
What causes CVE-2024-35284?
CVE-2024-35284 is caused by insufficient input validation in the legacy chat component of Mitel MiContact Center Business.