CVE-2025-27828: XSS
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4, 10.1.0.0 through 10.1.0.5, and 10.2.0.0 through 10.2.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction and could allow an attacker to execute arbitrary scripts with a limited impact on the confidentiality and the integrity.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27828?
CVE-2025-27828 is considered a moderate severity vulnerability because it allows unauthenticated attackers to perform reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-27828?
To fix CVE-2025-27828, users should upgrade Mitel MiContact Center Business to version 10.2.0.5 or later, which contains the necessary patches.
What versions of Mitel MiContact Center Business are affected by CVE-2025-27828?
CVE-2025-27828 affects Mitel MiContact Center Business versions up to 10.0.0.4, 10.1.0.0 through 10.1.0.5, and 10.2.0.0 through 10.2.0.4.
What type of attacks can occur due to CVE-2025-27828?
CVE-2025-27828 can be exploited to conduct reflected cross-site scripting (XSS) attacks, which may lead to data theft or manipulation.
Can I mitigate CVE-2025-27828 without an upgrade?
Mitigation options for CVE-2025-27828 may include implementing input validation and web application firewalls, but upgrading to a patched version is strongly recommended.