4.3
CVSSv2

CVE-2019-9593

Published: 06/03/2019 Updated: 07/10/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote malicious users to inject arbitrary web script or HTML via the page parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mitel connect onsite 18.82.2000.0

Exploits

# Exploit Title: Shoretel Connect Multiple Vulnerability # Google Dork: inurl:/signinphp?ret= # Date: 14/06/2017 # Author: Ramikan # Vendor Homepage: wwwshoretelcom/ # Software Link: wwwshoretelcom/resource-center/shoretel-connect-onsite-overview # Version: Tested on 186220000, 194551010, 194790000, 194884000 can be ...
ShoreTel Connect ONSITE versions prior to 194915000 suffer from cross site scripting and session fixation vulnerabilities ...