HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2025-67823

CVSS 8.2v3.1pub. 2026-01-15upd. 2026-01-23

A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction where the email channel is enabled. This could allow an attacker to execute arbitrary scripts in the victim's browser or desktop client application.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
  • Mitel Cx

    APP
    Mitel
    < 2.0
  • Mitel Micontact Center Business

    APP
    Mitel
    < 10.2.0.11
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XSSAuth Bypass
CWE
References

Related vulnerabilities

CVE-2021-3352CRITICAL9.1PL ✓same product

Auth Bypass w SDK Mitel MiContact Center Business — nieautoryzowany dostęp do danych

CVE-2024-42514HIGH8.1same product

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow a...

CVE-2024-28069HIGH7.5same product

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow a...

CVE-2023-22854HIGH7.5same product

The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthen...

CVE-2020-24692HIGH7.1same product

The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitra...