A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction where the email channel is enabled. This could allow an attacker to execute arbitrary scripts in the victim's browser or desktop client application.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mitel
Mitel micontact Center Business |
|
| Vendors & Products |
Mitel
Mitel micontact Center Business |
Thu, 15 Jan 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction where the email channel is enabled. This could allow an attacker to execute arbitrary scripts in the victim's browser or desktop client application. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-01-15T00:00:00.000Z
Updated: 2026-01-16T15:02:06.780Z
Reserved: 2025-12-12T00:00:00.000Z
Link: CVE-2025-67823
Updated: 2026-01-16T15:01:39.336Z
Status : Awaiting Analysis
Published: 2026-01-15T22:16:11.117
Modified: 2026-01-16T15:55:12.257
Link: CVE-2025-67823
No data.