Mitel
Mitel Connect Onsite: vulnerabilities and CVEs
Mitel Connect Onsite has 7 published vulnerabilities, 0 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months0
Critical4
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9593 | Medium (6.1) | 4.4% | — | Mar 6, 2019 | A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter. |
| CVE-2019-9592 | Medium (6.1) | 5.3% | — | Mar 6, 2019 | A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter. |
| CVE-2019-9591 | Medium (6.1) | 5.3% | — | Mar 6, 2019 | A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter. |
| CVE-2018-5782 | Critical (9.8) | 19% | — | Mar 14, 2018 | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using… |
| CVE-2018-5781 | Critical (9.8) | 1.7% | — | Mar 14, 2018 | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using… |
| CVE-2018-5780 | Critical (9.8) | 1.7% | — | Mar 14, 2018 | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using… |
| CVE-2018-5779 | Critical (9.8) | 2.7% | — | Mar 14, 2018 | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to copy a malicious script… |