Impact
The vulnerability is a stored XSS flaw in the web portal of Mitel MiVoice Office 400, located in the "Microsoft Exchange mailbox" field of the user list. An authenticated attacker can inject persistent JavaScript or HTML that is rendered whenever the affected user properties are accessed, leading to a denial‑of‑service within the application's user‑management interface.
Affected Systems
The affected product is Mitel MiVoice Office 400, specifically the web interface served over TCP port 443. The flaw resides in the Configuration → Users → Users List section, and no specific product versions are listed as vulnerable.
Risk and Exploitability
The CVSS score is 1.9, indicating low severity. The EPSS score is not available and the entry is not listed in CISA’s KEV catalog, suggesting a low likelihood of exploitation. The attack requires a user to be authenticated to the system and to possess the ability to modify the Microsoft Exchange mailbox field, so the attack vector is user‑based within the application. While the impact may be limited to denial‑of‑service and possible injection of malicious content for legitimate users, the overall risk remains low based on the available metrics.
OpenCVE Enrichment