Mitel

Connect Onsite

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 4.4%
  • Veröffentlicht 06.03.2019 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:51:55

A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter.

Exploit
  • EPSS 4.4%
  • Veröffentlicht 06.03.2019 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:51:55

A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

Exploit
  • EPSS 3.29%
  • Veröffentlicht 06.03.2019 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:51:55

A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

  • EPSS 2.12%
  • Veröffentlicht 14.03.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:09:22

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to copy a malicious script into a newly generated PHP file an...

  • EPSS 1.12%
  • Veröffentlicht 14.03.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:09:22

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vn...

  • EPSS 1.12%
  • Veröffentlicht 14.03.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:09:22

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the ve...

Exploit
  • EPSS 32.34%
  • Veröffentlicht 14.03.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:09:23

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vs...