Impact
An unauthenticated reflected cross‑site scripting vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (build 104997). The portal parameter passed to the invalid_browser and invalid_browser_login handlers is not sanitized, causing user‑supplied data to be reflected directly into JavaScript generated by the application. This enables an attacker to execute arbitrary script code within a victim’s browser session.
Affected Systems
Sangoma Switchvox SMB Edition 8.3 (build 104997).
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity vulnerability. An attacker can exploit it via an unauthenticated web request by crafting a URL with a malicious portal parameter that targets the vulnerable endpoints and causes the victim’s browser to run injected JavaScript. The EPSS score of less than 1% reflects a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment