CVE-2025-67823 Details
Description
A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction where the email channel is enabled. This could allow an attacker to execute arbitrary scripts in the victim's browser or desktop client application.
A cross-site scripting (XSS) vulnerability exists in the Multimedia Email component of Mitel MiContact Center Business versions through 10.2.0.10 and Mitel CX versions through 1.1.0.1. This vulnerability allows an unauthenticated attacker to perform a stored XSS attack due to inadequate input validation. Exploitation requires user interaction and the email channel to be enabled, potentially enabling the attacker to execute arbitrary scripts in the victim's browser or desktop client.
Users of MiContact Center Business should upgrade to version 10.2 FP 11 (10.2.0.11) or later, or to one of the earlier versions 10.2.0.10, 10.1.0.5, 10.0.0.4, or 9.5.0.3, and apply the corresponding hotfix. Users of Mitel CX should upgrade to version 2.0 or later when available, or to version 1.1.0.1 and apply the provided hotfix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.mitel.com/support/security-advisories | [email protected] | Vendor Advisory |
| https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2025-0010 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mitel cx | < 2.0 |
CPE
Remediation
| |
| mitel micontact center business | < 10.2.0.11 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 23, 2026 | Initial Analysis | [email protected] |
| Jan 16, 2026 | CVE Modified | CISA-ADP |
| Jan 15, 2026 | New CVE Received | [email protected] |