PT-2020-10150 · Mitel · Mitel Micollab Awv

Published

2020-03-02

·

Updated

2020-03-04

·

CVE-2019-19371

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mitel MiCollab AWV versions prior to 8.1.2.2
Description A cross-site scripting (XSS) issue exists due to insufficient validation in the join meeting interface of the web conferencing component. This could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack, potentially executing arbitrary scripts.
Recommendations For versions prior to 8.1.2.2, update to version 8.1.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the join meeting interface until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19371

Affected Products

Mitel Micollab Awv