CVE-2020-28351

MEDIUM NUCLEI

Mitel ShoreTel 19.46.1802.0 - Unauthenticated Reflected Cross-Site Scripting via PATH_INFO to index.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2020-28351. PoCs published by Joe Helle, dievus. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Mitel ShoreTel Conferencing 19.46.1802.0 via the PATH_INFO to index.php. The payload executes when the mouse hovers over a time_zone dropdown object on the HOME_MEETINGS page.

Description

The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack (via the PATH_INFO to index.php) due to insufficient validation for the time_zone object in the HOME_MEETING& page.

Exploits (2)

exploitdb WORKING POC
by Joe Helle · textwebappsphp
https://www.exploit-db.com/exploits/49026

This exploit demonstrates a reflected XSS vulnerability in Mitel ShoreTel Conferencing 19.46.1802.0 via the PATH_INFO to index.php. The payload executes when the mouse hovers over a time_zone dropdown object on the HOME_MEETINGS page.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Mitel ShoreTel Conferencing 19.46.1802.0
No auth needed
Prerequisites: Access to the vulnerable ShoreTel Conferencing web interface
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 3 stars
by dievus · poc
https://github.com/dievus/CVE-2020-28351

This repository contains a writeup describing a reflected XSS vulnerability in Mitel ShoreTel 19.46.1802.0. The vulnerability is triggered via the PATH_INFO in index.php, specifically through the time_zone object in the HOME_MEETINGS page.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Mitel ShoreTel 19.46.1802.0
No auth needed
Prerequisites: Access to the vulnerable ShoreTel web interface
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Mitel ShoreTel 19.46.1802.0 Devices - Cross-Site Scripting
MEDIUMby pikpikcu
FOFA: body="ShoreTel" && icon_hash="268280373"

References (3)

Core 3

Scores

CVSS v3 6.1
EPSS 0.1599
EPSS Percentile 96.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
mitel/shoretel_firmware 19.46.1802.0
Published Nov 09, 2020
Tracked Since Feb 18, 2026