Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-67823

29
FAUCET Score

CVE-2025-67823 is a high-severity Cross-Site Scripting (XSS) vulnerability affecting the Multimedia Email component of Mitel MiContact Center Business through version 10.2.0.10 and Mitel CX through 1.1.0.1. This flaw, rated 8.2 HIGH on the CVSS scale, allows an unauthenticated attacker to execute arbitrary scripts in a victim's browser or desktop client application due to insufficient input validation. Successful exploitation requires user interaction, specifically when the email channel is enabled. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in the CISA KEV catalog, indicating no active exploitation. However, the vulnerability has garnered significant community discussion, with 10 mentions, suggesting notable awareness within the cybersecurity community.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.0CPE matchmatch criteria
cpe:2.3:a:mitel:cx:*:*:*:*:*:*:*:*
< 10.2.0.11CPE matchmatch criteria
cpe:2.3:a:mitel:micontact_center_business:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.29%
Probability of exploitation in next 30 days
EPSS Percentile
21.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0029 is in the 25th percentile among its peer group of 14,848 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

nessuspatch availablevia llm_extracted
View patch
flaskvendor investigatingvia llm_extracted
hanwhavendor investigatingvia llm_extracted
mattermostvendor investigatingvia llm_extracted
mozillavendor investigatingvia llm_extracted

Vendor Advisories (5)

hanwhallm-hanwha-c9f89f57ce463412HIGH

MiContact Center Business and Mitel CX Cross Site Scripting (XSS) Vulnerability

Dec 9, 2025
flaskllm-flask-db05957218c80e5cHIGH

MiContact Center Business and Mitel CX Cross Site Scripting (XSS) Vulnerability

Dec 9, 2025
mozillallm-mozilla-ef50824dc77d1f83HIGH

MiContact Center Business and Mitel CX Cross Site Scripting (XSS) Vulnerability

Dec 9, 2025
mattermostllm-mattermost-d204ef7738ae7a56HIGH

MiContact Center Business and Mitel CX Cross Site Scripting (XSS) Vulnerability

Dec 9, 2025
nessusllm-nessus-acf4b25b8e9aca06HIGH

MiContact Center Business and Mitel CX Cross Site Scripting (XSS) Vulnerability

Dec 9, 2025

References

mitel.com / support/security-advisories
Vendor Advisory
mitel.com / support/security-advisories/mitel-product-security-advisory-misa-2025-0010
Vendor Advisory