Executive brief
Sangoma Switchvox SMB Edition, a business phone system, contains a security flaw that allows attackers to execute malicious scripts in a user's web browser. By tricking a user into clicking a specially crafted link, an unauthenticated attacker could potentially steal session information or perform actions on behalf of the user. This vulnerability affects the web portal used by employees and administrators to manage communications.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The vulnerability is located in the invalid_browser and invalid_browser_login handlers, which fail to properly sanitize the 'portal' parameter. User-supplied data from this parameter is reflected into JavaScript generated by the application. An unauthenticated remote attacker can exploit this by inducing a user to visit a malicious URL, leading to the execution of arbitrary script code in the context of the victim's browser session. This can result in session hijacking or unauthorized actions within the web portal. The issue is resolved in version 8.4.0.2.
Affected products
- Sangoma Switchvox SMB Edition 8.3 (104997) before 8.4.0.2
Timeline
- 2026-05-11: disclosed: SRA begins submitting vulnerabilities to vendor
- 2026-06-02: other: Vendor acknowledges vulnerabilities and intent to fix
- 2026-07-14: patched: Vendor releases version 8.4.0.2 fix
- 2026-07-17: advisory: SRA and NVD publish advisory details