PT-2018-6262 · Mitel · Mitel St
Published
2018-03-13
·
Updated
2018-09-07
·
CVE-2017-16251
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Mitel ST 14.2, release GA28 and earlier
Description:
A vulnerability in the conferencing component could allow an authenticated user to upload a malicious script to the Personal Library by a crafted POST request to an unspecified API endpoint. Successful exploitation could allow an attacker to execute arbitrary code within the context of the application.
Recommendations:
For Mitel ST 14.2, release GA28 and earlier, consider restricting access to the Personal Library and limiting the ability to upload scripts until a fix is available. As a temporary workaround, consider disabling the script upload functionality to minimize the risk of exploitation.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mitel St