A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4, 10.1.0.0 through 10.1.0.5, and 10.2.0.0 through 10.2.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction and could allow an attacker to execute arbitrary scripts with a limited impact on the confidentiality and the integrity.
CVE ID: CVE-2025-27828
Vendor: n/a
Product: n/a
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 12.35% (scored less or equal to compared to others)
EPSS Date: 2025-07-03 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: false