VYPR
High severity7.4NVD Advisory· Published May 24, 2023· Updated Jun 17, 2026

CVE-2023-25599

CVE-2023-25599

Description

A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2, 22.24.1500.0 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the test_presenter.php page. A successful exploit could allow an attacker to execute arbitrary scripts.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:mitel:mivoice_connect:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mitel:mivoice_connect:*:*:*:*:*:*:*:*range: <=22.24.1500.0
    • (no CPE)range: <=19.3 SP2, <=22.24.1500.0
  • Mitel/MiVoice Connectdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.