CVE-2025-67823
8.2Mitel · MiContact Center Business and CX
A cross-site scripting vulnerability in Mitel MiContact Center Business and CX allows unauthenticated attackers to execute arbitrary scripts in a victim's browser or desktop application.
Executive summary
A high-severity cross-site scripting vulnerability in Mitel MiContact Center Business and CX enables unauthenticated attackers to execute malicious scripts via the Multimedia Email component.
Vulnerability
The vulnerability is a cross-site scripting (XSS) flaw caused by insufficient input validation within the Multimedia Email component, which allows an unauthenticated attacker to inject malicious scripts that execute in the context of a victim's session.
Business impact
Successful exploitation allows an attacker to execute arbitrary scripts within the victim's browser or desktop client, potentially leading to session hijacking, sensitive data exposure, or unauthorized actions performed on behalf of the user. With a CVSS score of 8.2, this vulnerability represents a significant risk to organizational integrity, as it can be leveraged to compromise user accounts and internal communications within the contact center environment.
Remediation
Immediate Action: Review the official Mitel security advisory portal at the provided references to identify and apply the specific security patches or configuration changes required for your environment.
Proactive Monitoring: Monitor network and application logs for unusual script injections or unexpected outbound traffic patterns originating from the MiContact Center interface.
Compensating Controls: Deploy or update Web Application Firewall rules to detect and block common XSS payloads directed at the email processing components of the contact center software.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for unauthorized script execution and the high CVSS severity score, organizations should prioritize the evaluation of their Mitel deployments. Administrators must consult the vendor's security advisory pages immediately to determine the availability of patches and apply them as soon as they are released to prevent potential exploitation.