Mitel has released advisory MISA-2025-0003 regarding CVE-2025-27828, rated high severity.

  • Advisory: MISA-2025-0003

  • The vendor's own summary: MiContact Center Business Reflected Cross Site Scripting Vulnerability

  • Vendor severity: high

  • CVE: CVE-2025-27828

  • Published by the vendor: 2025-03-26

  • Last revised by the vendor: 2025-06-18

Leonidas tracks the security advisories published by the vendors whose equipment we resell, install and support. We read each one against the systems we manage and plan any remediation with the client it belongs to, as part of that engagement.

This notice is assembled from the vendor's own advisory index and nothing else. We do not hold the list of products and versions an advisory affects: the vendor summary above is their index entry, not a statement of scope, and an advisory often covers more than the products that entry happens to name. The vendor's advisory, linked below, is the authoritative source, the complete list of what is affected, and the version to act on.

Mitel security advisory MISA-2025-0003