Executive brief
Sangoma Switchvox is a business phone system used for managing corporate communications. A security flaw in the voicemail notification system allows an authorized user to inject malicious code into notification templates. If another user views these templates, the code could execute in their browser, potentially leading to unauthorized actions or data theft within the management portal.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the voicemail notification template functionality of Sangoma Switchvox SMB Edition. The 'submit_modify_voicemail_template' endpoint fails to properly sanitize HTML content provided in the 'template_text' parameter. An authenticated attacker can submit malicious JavaScript that is stored on the server and executed in the context of other users' browsers when they view the affected template. This vulnerability is fixed in version 8.4.0.2.
Affected products
- Sangoma Switchvox SMB Edition 8.3 (104997) before 8.4.0.2
Timeline
- 2026-05-11: disclosed: SRA submits vulnerabilities to vendor
- 2026-06-02: other: Vendor acknowledges vulnerabilities
- 2026-07-14: patched: Vendor releases version 8.4.0.2
- 2026-07-17: advisory: SRA and NVD publish advisory details