Mitel ST 14.2 19.49.5200.0

CPE Details

Mitel ST 14.2 19.49.5200.0
19.49.5200.0
2018-05-24
13h18 +00:00
2021-04-15
12h31 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:mitel:st_14.2:19.49.5200.0:*:*:*:*:*:*:*

Informations

Vendor

mitel

Product

st_14.2

Version

19.49.5200.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-9101 2018-04-25 18h00 +00:00 A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the launch_presenter.php page. A successful exploit could allow an attacker to execute arbitrary scripts.
6.1
Medium
CVE-2018-9102 2018-04-25 18h00 +00:00 A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the signin interface. A successful exploit could allow an attacker to extract sensitive information from the database.
6.5
Medium
CVE-2018-9103 2018-04-25 18h00 +00:00 A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the signin.php page. A successful exploit could allow an attacker to execute arbitrary scripts.
6.1
Medium
CVE-2018-9104 2018-04-25 18h00 +00:00 A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the api.php page. A successful exploit could allow an attacker to execute arbitrary scripts.
6.1
Medium