CVE-2025-27828
Description
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4, 10.1.0.0 through 10.1.0.5, and 10.2.0.0 through 10.2.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction and could allow an attacker to execute arbitrary scripts with a limited impact on the confidentiality and the integrity.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A reflected XSS vulnerability in Mitel MiContact Center Business legacy chat component could allow unauthenticated attackers to execute arbitrary scripts via insufficient input validation requiring user interaction.
A reflected cross-site scripting (XSS) vulnerability has been identified in the Legacy Chat component of Mitel MiContact Center Business, due to insufficient input validation [2]. This vulnerability affects versions 10.0.0.0 through 10.0.0.4, 10.1.0.0 through 10.1.0.5, 10.2.0.0 through 10.2.0.4, and 9.5.0.3 and earlier [2].
Exploitation of this vulnerability does not require authentication, but does require user interaction, such as clicking a specially crafted link [2]. An unauthenticated attacker can inject arbitrary scripts into the chat component, which will be reflected back to the victim's browser.
Successful exploitation could allow an attacker to execute arbitrary scripts with limited impact on confidentiality and integrity, potentially enabling the attacker to obtain sensitive information or modify the current chat session [2]. The CVSS v3.1 base score is 7.1, rated as high severity [2].
Mitel has released upgrades and hotfixes to address this issue. Customers should upgrade to MiContact Center Business version 10.2.0.5 or later, or apply hotfixes KB571322, KB571372, or KB571320 for specific releases [2].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.