Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104807— Mitel MiVoice Office 400 stored Cross-Site Scripting

Quick assessment

Affected
Mitel Mitel MiVoice Office 400
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Digital Canyon 发现了一个存储型跨站脚本(XSS)漏洞,该漏洞允许经过身份验证的恶意用户在 Web 应用中注入持久的 JavaScript 或 HTML 内容。 该特定缺陷存在于监听 TCP 端口 443 的 Web 门户中,具体位于“配置(Configuration)→ 域名(Domains)”下的“描述(Description)”字段。应用在存储和后续渲染该字段时,未能正确验证或清理用户提供的输入。 通过在“描述”字段中注入恶意 JavaScript 代码,攻击者在其他用户查看受影响页面时,可以修

CVSS 1.9 · Low
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104807

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Mitel MiVoice Office 400 stored Cross-Site Scripting
Source: CVE Program / CVE List V5
Vulnerability Description
DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content into the web application. The specific flaw exists within the web portal listening on TCP port 443, under Configuration → Domains, specifically in the “Description” field. The application fails to properly validate or sanitize user-supplied input before storing and subsequently rendering the field. By injecting malicious JavaScript into the Description field, an attacker can modify the content and behavior of the affected page when it is viewed by other users. This could allow an attacker to alter the page's appearance, display attacker-controlled content, or construct convincing phishing scenarios within the application's trusted web context.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/AU:Y/R:A/V:D/RE:L/U:Amber
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Mitel Mitel MiVoice Office 400 11.0.96.0 -

II. Public POCs for CVE-2026-104807

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104807

请登录查看更多情报信息。

Other References for CVE-2026-104807 (1)

Same Patch Batch · Mitel · 2026-10-05 · 8 CVEs total

CVE-2026-104805 8.5 HIGH Mitel MiVoice Office 400 Backup Restoration Arbitrary File Write Leading to Root Code Exec
CVE-2026-104706 8.4 HIGH Mitel MiVoice Office 400 view system files path traversal
CVE-2026-104810 8.4 HIGH Mitel MiVoice Office 400 File Management File Browser path traversal vulnerability
CVE-2026-104809 8.4 HIGH Mitel MiVoice Office 400 Shared Object Hijacking Leading to Arbitrary Code Execution
CVE-2026-104811 8.4 HIGH Mitel MiVoice Office 400 Music on Hold WAV File Upload Code Execution
CVE-2026-104806 5.5 MEDIUM Mitel MiVoice Office 400 System Logs Path Traversal Information Disclosure
CVE-2026-104808 1.9 LOW Mitel MiVoice Office 400 stored Cross-Site Scripting

IV. Related Vulnerabilities

V. Comments for CVE-2026-104807

No comments yet


Leave a comment