Description
DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content into the web application.




The specific flaw exists within the web portal listening on TCP port 443, under Configuration → Domains, specifically in the “Description” field. The application fails to properly validate or sanitize user-supplied input before storing and subsequently rendering the field.




By injecting malicious JavaScript into the Description field, an attacker can modify the content and behavior of the affected page when it is viewed by other users. This could allow an attacker to alter the page's appearance, display attacker-controlled content, or construct convincing phishing scenarios within the application's trusted web context.
Published: 2026-10-05
Score: 1.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Mitel
Mitel mivoice Office 400
Vendors & Products Mitel
Mitel mivoice Office 400

Mon, 05 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content into the web application. The specific flaw exists within the web portal listening on TCP port 443, under Configuration → Domains, specifically in the “Description” field. The application fails to properly validate or sanitize user-supplied input before storing and subsequently rendering the field. By injecting malicious JavaScript into the Description field, an attacker can modify the content and behavior of the affected page when it is viewed by other users. This could allow an attacker to alter the page's appearance, display attacker-controlled content, or construct convincing phishing scenarios within the application's trusted web context.
Title Mitel MiVoice Office 400 stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 1.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/AU:Y/R:A/V:D/RE:L/U:Amber'}


Subscriptions

Mitel Mivoice Office 400
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-10-05T13:11:29.180Z

Reserved: 2026-10-02T13:47:47.692Z

Link: CVE-2026-104807

cve-icon Vulnrichment

Updated: 2026-10-05T13:11:25.839Z

cve-icon NVD

Status : Deferred

Published: 2026-10-05T09:17:09.690

Modified: 2026-10-06T15:18:12.170

Link: CVE-2026-104807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:45:05Z

Weaknesses