CRITICAL
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vendrecording.php page
Published Mar 14, 2018
9.8
CRITICALCVSS 3.0
EPSS 1.73%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.