CVE-2019-9591
- EPSS 4.4%
- Veröffentlicht 06.03.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:51:55
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter.
CVE-2019-9592
- EPSS 4.4%
- Veröffentlicht 06.03.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:51:55
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
CVE-2019-9593
- EPSS 3.29%
- Veröffentlicht 06.03.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:51:55
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
- EPSS 2.12%
- Veröffentlicht 14.03.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:22
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to copy a malicious script into a newly generated PHP file an...
- EPSS 1.12%
- Veröffentlicht 14.03.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:22
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vn...
- EPSS 1.12%
- Veröffentlicht 14.03.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:22
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the ve...
- EPSS 32.34%
- Veröffentlicht 14.03.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:23
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vs...