Impact
A stored cross‑site scripting (XSS) vulnerability exists in the voicemail notification template functionality of Sangoma Switchvox SMB Edition 8.3. The submit_modify_voicemail_template endpoint fails to sanitize HTML content supplied by authenticated users, allowing malicious JavaScript to be stored server‑side and rendered to other users. This flaw can lead to arbitrary script execution in the victim’s browser, as it exploits a classic CWE‑79 weakness in input handling.
Affected Systems
The vulnerability is present in Sangoma Switchvox SMB Edition 8.3 (build 104997). Users running this specific version are potentially exposed, while newer releases that address the issue are not affected.
Risk and Exploitability
The CVSS score of 7.0 indicates a high severity, but the EPSS score of less than 1% suggests that exploitation is currently unlikely. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to be an authenticated user with permission to modify voicemail templates; the attacker then submits a crafted template containing malicious script, which is stored and later rendered to other users’ browsers. The attack vector is therefore a web‑based authenticated interaction with the Switchvox portal.
OpenCVE Enrichment