Description
DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content into the web application.




The specific flaw exists within the web portal listening on TCP port 443, under Configuration → Domains, specifically in the “Description” field. The application fails to properly validate or sanitize user-supplied input before storing and subsequently rendering the field.




By injecting malicious JavaScript into the Description field, an attacker can modify the content and behavior of the affected page when it is viewed by other users. This could allow an attacker to alter the page's appearance, display attacker-controlled content, or construct convincing phishing scenarios within the application's trusted web context.
Published: 2026-10-05
Score: 1.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting in Mitel MiVoice Office 400 web portal
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw in the Mitel MiVoice Office 400 web portal. An authenticated user can inject JavaScript or HTML into the Description field under Configuration → Domains. When other users view the domain configuration page, the malicious content is rendered, allowing the attacker to alter the page’s appearance or display attacker‑controlled content. The description notes that this could enable convincingly phishing scenarios within the application’s trusted web context.

Affected Systems

All deployments of Mitel MiVoice Office 400 that expose the web portal on port 443 are affected. The flaw resides in the Description field of the Domains configuration page; any installation that permits editing of this field is vulnerable. No specific version range is supplied, so all current releases remain at risk until a patch is issued.

Risk and Exploitability

The CVSS score of 1.9 indicates low overall risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session with edit rights to the Description field. Though the impact primarily involves user‑interface manipulation and potential phishing within the trusted domain, it could compromise user trust and lead to social‑engineering attacks. Restricting permissions for editing the Description field or applying input validation mitigates the risk.

Generated by OpenCVE AI on October 5, 2026 at 11:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑issued security patch for Mitel MiVoice Office 400 when it becomes available.
  • If a patch is not yet available, restrict or remove edit permissions for the Description field in the Domains configuration section.
  • Implement input validation and output escaping on the Description field, and consider configuring a web application firewall to block injected scripts.

Generated by OpenCVE AI on October 5, 2026 at 11:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content into the web application. The specific flaw exists within the web portal listening on TCP port 443, under Configuration → Domains, specifically in the “Description” field. The application fails to properly validate or sanitize user-supplied input before storing and subsequently rendering the field. By injecting malicious JavaScript into the Description field, an attacker can modify the content and behavior of the affected page when it is viewed by other users. This could allow an attacker to alter the page's appearance, display attacker-controlled content, or construct convincing phishing scenarios within the application's trusted web context.
Title Mitel MiVoice Office 400 stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 1.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/AU:Y/R:A/V:D/RE:L/U:Amber'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-10-05T13:11:29.180Z

Reserved: 2026-10-02T13:47:47.692Z

Link: CVE-2026-104807

cve-icon Vulnrichment

Updated: 2026-10-05T13:11:25.839Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:09.690

Modified: 2026-10-05T14:17:16.313

Link: CVE-2026-104807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T11:15:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')