ZeroHour

CVE-2019-9591

PoC ×3
CVSS 3.1
6.1 medium
EPSS
5%p92
Published
()
Modified
Description

A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter.

Vendors
mitel
Products
connect onsite
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.