Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-9591. PoCs published by Ramikan.
AI-analyzed exploit summary The provided text describes multiple reflected XSS and session fixation vulnerabilities in Shoretel Connect software. It includes affected URLs, parameters, and versions, but does not contain executable exploit code.
Description
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter.
Exploits (1)
The provided text describes multiple reflected XSS and session fixation vulnerabilities in Shoretel Connect software. It includes affected URLs, parameters, and versions, but does not contain executable exploit code.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N