VYPR
Medium severity6.5NVD Advisory· Published Aug 13, 2021· Updated Jun 17, 2026

CVE-2021-27402

CVE-2021-27402

Description

The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify) user data by injecting arbitrary directory paths due to improper URL validation, aka Directory Traversal.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Mitel/Micollab4 versions
    cpe:2.3:a:mitel:micollab:*:*:*:*:*:-:*:*+ 3 more
    • cpe:2.3:a:mitel:micollab:*:*:*:*:*:-:*:*range: <9.2
    • cpe:2.3:a:mitel:micollab:9.2:-:*:*:*:-:*:*
    • cpe:2.3:a:mitel:micollab:9.2:fp1:*:*:*:-:*:*
    • (no CPE)range: <9.2 FP2
  • Mitel/MiCollabdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.