CVE-2020-24692

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
25/09/2020
Last modified:
21/07/2021

Description

The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain access to a user session.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mitel:micontact_center_business:*:*:*:*:*:*:*:* 9.3.0.0 (excluding)