Impact
The vulnerability is a stored cross‑site scripting flaw in the Mitel MiVoice Office 400 web portal. An authenticated user can inject JavaScript or HTML into the Description field under Configuration → Domains. When other users view the domain configuration page, the malicious content is rendered, allowing the attacker to alter the page’s appearance or display attacker‑controlled content. The description notes that this could enable convincingly phishing scenarios within the application’s trusted web context.
Affected Systems
All deployments of Mitel MiVoice Office 400 that expose the web portal on port 443 are affected. The flaw resides in the Description field of the Domains configuration page; any installation that permits editing of this field is vulnerable. No specific version range is supplied, so all current releases remain at risk until a patch is issued.
Risk and Exploitability
The CVSS score of 1.9 indicates low overall risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session with edit rights to the Description field. Though the impact primarily involves user‑interface manipulation and potential phishing within the trusted domain, it could compromise user trust and lead to social‑engineering attacks. Restricting permissions for editing the Description field or applying input validation mitigates the risk.
OpenCVE Enrichment