vendor:
Shoretel Connect
by:
Ramikan
6.1
CVSS
MEDIUM
Reflected XSS and Session Fixation
79
CWE
Product Name: Shoretel Connect
Affected Version From: 18.62.2000.0
Affected Version To: 19.48.8400.0
Patch Exists: YES
Related CWE: CVE-2019-9591, CVE-2019-9592, CVE-2019-9593
CPE: a:shoretel:shoretel_connect
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Mozila Firefox 53.0.3 (32 bit)
2017
Exploit Title: Shoretel Connect Multiple Vulnerability
A reflected XSS vulnerability exists in Shoretel Connect versions 18.62.2000.0, 19.45.5101.0, 19.47.9000.0, 19.48.8400.0. An attacker can exploit this vulnerability by sending a malicious URL to the victim. The malicious URL contains a malicious script which will be executed in the victim's browser. The attacker can also hijack the session of the user by exploiting the XSS vulnerability.
Mitigation:
Update to 19.49.1500.0