VYPR

Micollab

by Mitel

CVEs (54)

  • CVE-2020-13863HigAug 26, 2020
    risk 0.53cvss 8.1epss 0.01

    The SAS portal of Mitel MiCollab before 9.1.3 could allow an attacker to access user data by performing a header injection in HTTP responses, due to the improper handling of input parameters. A successful exploit could allow an attacker to access user information.

  • CVE-2024-47189HigOct 21, 2024
    risk 0.50cvss 7.7epss 0.00

    The API Interface of the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct SQL injection due to insufficient sanitization of user input. A successful exploit could allow an…

  • CVE-2020-11797HigAug 26, 2020
    risk 0.49cvss 7.5epss 0.01

    An Authentication Bypass vulnerability in the Published Area of the web conferencing component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an unauthenticated attacker to gain access to unauthorized information due to insufficient access validation. A…

  • CVE-2024-30158HigOct 21, 2024
    risk 0.47cvss 7.2epss 0.00

    A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a SQL Injection attack due to insufficient validation of user input. A successful exploit could allow an attacker…

  • CVE-2024-30157HigOct 21, 2024
    risk 0.47cvss 7.2epss 0.00

    A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a SQL Injection attack due to insufficient validation of user input. A successful exploit could allow…

  • CVE-2020-25608HigDec 18, 2020
    risk 0.47cvss 7.2epss 0.01

    The SAS portal of Mitel MiCollab before 9.2 could allow an attacker to access user credentials due to improper input validation, aka SQL Injection.

  • CVE-2024-35287MedOct 21, 2024
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8 SP1 (9.8.1.5) could allow an authenticated attacker with administrative privilege to conduct a privilege escalation attack due to the execution of a resource with unnecessary…

  • CVE-2018-3639MedMay 22, 2018
    risk 0.44cvss 5.5epss 0.61

    Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis,…

  • CVE-2024-41712MedOct 21, 2024
    risk 0.43cvss 6.6epss 0.01

    A vulnerability in the Web Conferencing Component of Mitel MiCollab through 9.8.1.5 could allow an authenticated attacker to conduct a command injection attack, due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary…

  • CVE-2024-47224MedOct 21, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a CRLF injection attack due to inadequate encoding of user input in URLs. A successful exploit could…

  • CVE-2022-36454MedOct 25, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper authorization controls. A successful exploit could allow the authenticated attacker to impersonate another…

  • CVE-2021-32072MedAug 13, 2021
    risk 0.42cvss 6.5epss 0.01

    The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to get source code information (disclosing sensitive application data) due to insufficient output sanitization. A successful exploit could allow an attacker to view source code methods.

  • CVE-2021-32067MedAug 13, 2021
    risk 0.42cvss 6.5epss 0.01

    The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to view sensitive system information through an HTTP response due to insufficient output sanitization.

  • CVE-2021-27402MedAug 13, 2021
    risk 0.42cvss 6.5epss 0.01

    The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify) user data by injecting arbitrary directory paths due to improper URL validation, aka Directory Traversal.

  • CVE-2020-11798MedJun 10, 2020
    risk 0.41cvss 5.3epss 0.45

    A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A…

  • CVE-2021-27401MedAug 13, 2021
    risk 0.40cvss 6.1epss 0.01

    The Join Meeting page of Mitel MiCollab Web Client before 9.2 FP2 could allow an attacker to access (view and modify) user data by executing arbitrary code due to insufficient input validation, aka Cross-Site Scripting (XSS).

  • CVE-2020-27340MedDec 18, 2020
    risk 0.40cvss 6.1epss 0.01

    The online help portal of Mitel MiCollab before 9.2 could allow an attacker to redirect a user to an unauthorized website by executing malicious script due to insufficient access control.

  • CVE-2020-25611MedDec 18, 2020
    risk 0.40cvss 6.1epss 0.01

    The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending arbitrary code due to improper input validation, aka XSS. Successful exploitation could allow an attacker to view user conference information.

  • CVE-2020-25606MedDec 18, 2020
    risk 0.40cvss 6.1epss 0.01

    The AWV component of Mitel MiCollab before 9.2 could allow an attacker to view system information by sending arbitrary code due to improper input validation, aka XSS.

  • CVE-2019-19371MedMar 2, 2020
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation in the join meeting interface. A…