S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-28351 Scanner

CVE-2020-28351 scanner - Cross-Site Scripting (XSS) vulnerability in Mitel ShoreTel

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
4.6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-28351
6.1
CVSS

The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack (via the PATH_INFO to index.php) due to insufficient validation for the time_zone object in the HOME_MEETING& page.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Mitel ShoreTel is a popular communication platform used in businesses to enable seamless connectivity and collaboration. With Mitel ShoreTel 19.46.1802.0, users can conduct conference calls, exchange messages, and share files and documents with ease. Mitel ShoreTel is a complete communication suite that plays a crucial role in ensuring that teams stay connected and productive, regardless of their location.

However, recently, a vulnerability known as CVE-2020-28351 has been detected in the conferencing component of Mitel ShoreTel. This vulnerability can allow an attacker to conduct a reflected cross-site scripting (XSS) attack by exploiting the lack of validation for the time_zone object in the HOME_MEETING page. As a result, attackers can inject malicious scripts into the system and execute them within the user's browser, leading to the theft of user credentials, sensitive data, and other malicious activities.

The exploitation of CVE-2020-28351 can lead to severe consequences for organizations that use Mitel ShoreTel. Attackers can disrupt communication channels, steal sensitive data, and cause financial losses to organizations. Furthermore, it can damage an organization's reputation and trustworthiness. Therefore, it is critical to ensure that the vulnerability is mitigated as soon as possible to prevent any potential harm to the organization.

At S4E, we care about the security of your digital assets. Our platform provides pro features that enable you to quickly and easily learn about vulnerabilities in your network, website, or other applications. By staying informed about the latest threats, you can take proactive measures to protect your organization's critical assets and ensure that your team remains productive and connected. Trust us to keep your organization's digital security on high alert.

 

REFERENCES

Solution Advice

Here are some precautions that can be taken to protect against CVE-2020-28351:

  • Update Mitel ShoreTel to the latest version, which includes a patch for this vulnerability.
  • Implement web application firewalls to prevent XSS attacks.
  • Avoid clicking on suspicious links or downloading files from unknown sources.
  • Use strong passwords and enable two-factor authentication to mitigate the risk of credential theft.
  • Conduct regular security audits and scans to detect vulnerabilities in the system.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.