Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-67823

Опубликовано: 15 янв. 2026
Источник: nvd
CVSS3: 8.2
EPSS Низкий

Описание

A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction where the email channel is enabled. This could allow an attacker to execute arbitrary scripts in the victim's browser or desktop client application.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mitel:cx:*:*:*:*:*:*:*:*
Версия до 2.0 (исключая)
cpe:2.3:a:mitel:micontact_center_business:*:*:*:*:*:*:*:*
Версия до 10.2.0.11 (исключая)

EPSS

Процентиль: 12%
0.0004
Низкий

8.2 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.2
github
23 дня назад

A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction where the email channel is enabled. This could allow an attacker to execute arbitrary scripts in the victim's browser or desktop client application.

EPSS

Процентиль: 12%
0.0004
Низкий

8.2 High

CVSS3

Дефекты

CWE-79