« Back to list

Mitel

Mitel Connect Onsite: vulnerabilities and CVEs

Mitel Connect Onsite has 7 published vulnerabilities, 0 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.

CVEs7
Last 12 months0
Critical4
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2019-9593Medium (6.1)4.4%—Mar 6, 2019
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CVE-2019-9592Medium (6.1)5.3%—Mar 6, 2019
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
CVE-2019-9591Medium (6.1)5.3%—Mar 6, 2019
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter.
CVE-2018-5782Critical (9.8)19%—Mar 14, 2018
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using…
CVE-2018-5781Critical (9.8)1.7%—Mar 14, 2018
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using…
CVE-2018-5780Critical (9.8)1.7%—Mar 14, 2018
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using…
CVE-2018-5779Critical (9.8)2.7%—Mar 14, 2018
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to copy a malicious script…

Other products by Mitel