CVE-2025-67823HIGH 8.2EPSS p20.7%

CVE-2025-67823CVE-2025-67823

Description

A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction where the email channel is enabled. This could allow an attacker to execute arbitrary scripts in the victim's browser or desktop client application.

Scoring

CVSS 3.18.2 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
EPSS0.29% probability of exploitation · percentile 20.7% · 2026-06-18T12:00:27Z
Published2026-01-15
Last modified2026-01-23

Underlying weaknesses· 1

CWE-79

References

  1. https://www.mitel.com/support/security-advisories
  2. https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2025-0010

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')cwe-790%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-20233
CVE
CVE-2025-44148
CVE
CVE-2025-52914
CVE
CVE-2025-67822
CVE
MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability
CVE
Mitel MiVoice Connect Data Validation Vulnerability
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.