Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-12901

A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the signin.php page. A successful exploit could allow an attacker to execute arbitrary scripts.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 48.7%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2018-12901
  • Mitel » St » Version: 14.2
    cpe:2.3:h:mitel:st:14.2
  • Mitel » St Firmware » Version: Any
    cpe:2.3:o:mitel:st_firmware:*


Contact Us

Shodan ® - All rights reserved