← Back

CVE-2018-5780

nvd nist
Published: Mar 14, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vnewmeeting.php page. Successful exploit could allow an attacker to execute arbitrary PHP code within the context of the application.

Affected (2)

2 products
Connect Onsite
St14.2
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to r1711-prem
Up to ga28

Timeline

No history available yet.