Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2018-5782 Details

Description

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vsethost.php page. Successful exploit could allow an attacker to execute arbitrary PHP code within the context of the application.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-94Improper Control of Generation of Code ('Code Injection')[email protected]

Affected Products

ProductVersions
mitel connect onsite
<= r1711-prem

CPE

  • cpe:2.3:a:mitel:connect_onsite:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
mitel st14.2
<= ga28

CPE

  • cpe:2.3:a:mitel:st14.2:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

8 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2018-5782
NVD Published Date:
Mar 14, 2018
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2018-5782 Details - Not Deferred