CVE-2025-67823 is a high-severity Cross-Site Scripting (XSS) vulnerability affecting the Multimedia Email component of Mitel MiContact Center Business through version 10.2.0.10 and Mitel CX through 1.1.0.1. This flaw, rated 8.2 HIGH on the CVSS scale, allows an unauthenticated attacker to execute arbitrary scripts in a victim's browser or desktop client application due to insufficient input validation. Successful exploitation requires user interaction, specifically when the email channel is enabled. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in the CISA KEV catalog, indicating no active exploitation. However, the vulnerability has garnered significant community discussion, with 10 mentions, suggesting notable awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0CPE matchmatch criteria | cpe:2.3:a:mitel:cx:*:*:*:*:*:*:*:* | ||
< 10.2.0.11CPE matchmatch criteria | cpe:2.3:a:mitel:micontact_center_business:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
MiContact Center Business and Mitel CX Cross Site Scripting (XSS) Vulnerability
Dec 9, 2025MiContact Center Business and Mitel CX Cross Site Scripting (XSS) Vulnerability
Dec 9, 2025MiContact Center Business and Mitel CX Cross Site Scripting (XSS) Vulnerability
Dec 9, 2025MiContact Center Business and Mitel CX Cross Site Scripting (XSS) Vulnerability
Dec 9, 2025MiContact Center Business and Mitel CX Cross Site Scripting (XSS) Vulnerability
Dec 9, 2025