CVE-2020-28351
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 16%
from disclosure to weapon0 days
Published on NVDNov 9
1st PoCNov 6
exploitation probability
16%top 3% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack (via the PATH_INFO to index.php) due to insufficient validation for the time_zone object in the HOME_MEETING& page.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/49026unverifiedgithubgithub.com/dievus/CVE-2020-28351★ 3cve_referencepacketstormsecurity.com/files/159987/ShoreTel-Conferencing-19.46.1802.0-Cross-Site-Scripting.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.