← Vulnerability feed

Vulnerability record · CVE-2018-5781 · published 14 March 2018

CVE-2018-5781: Mitel connect onsite code injection vulnerability

Mitel · Connect Onsite

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vendrecording.php page. Successful exploit could allow an attacker to execute arbitrary PHP code within the context of the application.

9.8 CVSS 3.0 Critical EPSS 1.7% · top 23.3% CWE-94 · Code injection
9.8CVSS 3.0 base score, v2 10.0
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vendrecording.php page. Successful exploit could allow an attacker to execute arbitrary PHP code within the context of the application.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-5781 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-5779Mitel connect onsite code injection vulnerabilityA vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …EPSS 2.7%9.8CVE-2018-5780Mitel connect onsite code injection vulnerabilityA vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …EPSS 1.7%9.8CVE-2018-5782Mitel connect onsite code injection vulnerabilityA vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …EPSS 19%8.8CVE-2017-16251Mitel st14.2 unrestricted file upload vulnerabilityA vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious scr…EPSS 1.8%6.1CVE-2019-9591Mitel connect onsite cross-site scripting vulnerabilityA reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web s…EPSS 5.3%6.1CVE-2019-9592Mitel connect onsite cross-site scripting vulnerabilityA reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script o…EPSS 5.3%6.1CVE-2019-9593Mitel connect onsite cross-site scripting vulnerabilityA reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script o…EPSS 4.4%5.3CVE-2017-16250Mitel st14.2 information exposure vulnerabilityA vulnerability in Mitel ST 14.2, release GA28 and earlier, could allow an attacker to use the API function to enumerate through user-ids which could…EPSS 0.85%

Source: NIST National Vulnerability Database (record CVE-2018-5781), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.