CyberRota Analysis
AI-GeneratedAn unauthenticated reflected cross-site scripting (XSS) vulnerability in Sangoma Switchvox SMB Edition version 8.3 allows attackers to inject malicious scripts through improperly sanitized user input in the portal parameter. This could lead to unauthorized script execution in the victim's browser, potentially compromising sensitive user information. Organizations using this version of Switchvox should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly sanitize the portal parameter supplied to the invalid_browser and invalid_browser_login handlers. User-supplied data is reflected into JavaScript generated by the application, allowing attacker-controlled script execution within a victim's browser.