VYPR

Micollab

by Mitel

CVEs (54)

  • CVE-2019-19370MedMar 2, 2020
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the web conferencing component of the Mitel MiCollab application before 9.0.15 for Android could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation in the file…

  • CVE-2024-55550LowKEVDec 10, 2024
    risk 0.39cvss 2.7epss 0.38

    Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to…

  • CVE-2023-25597MedApr 14, 2023
    risk 0.38cvss 5.9epss 0.01

    A vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shared file via a crafted request - including the exact path and filename - due to improper authentication control. A successful exploit…

  • CVE-2020-13767MedAug 26, 2020
    risk 0.38cvss 5.9epss 0.01

    The Mitel MiCollab application before 9.1.332 for iOS could allow an unauthorized user to access restricted files and folders due to insufficient access control. An exploit requires a rooted iOS device, and (if successful) could allow an attacker to gain access to sensitive…

  • CVE-2024-35315MedOct 21, 2024
    risk 0.36cvss 5.6epss 0.01

    A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an authenticated attacker to conduct a privilege escalation attack due to improper file validation. A successful exploit…

  • CVE-2021-32070MedAug 13, 2021
    risk 0.35cvss 5.4epss 0.01

    The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to perform a clickjacking attack due to an insecure header response. A successful exploit could allow an attacker to modify the browser header and redirect users.

  • CVE-2020-25610MedDec 18, 2020
    risk 0.35cvss 5.3epss 0.01

    The AWV component of Mitel MiCollab before 9.2 could allow an attacker to gain access to a web conference due to insufficient access control for conference codes.

  • CVE-2020-25609MedDec 18, 2020
    risk 0.35cvss 5.4epss 0.01

    The NuPoint Messenger Portal of Mitel MiCollab before 9.2 could allow an authenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to view and modify user data.

  • CVE-2018-18819MedNov 12, 2019
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP2 (8.0.2.202), and MiVoice Business Express versions 7.3 PR3 (7.3.1.302) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP1…

  • CVE-2020-25612MedDec 18, 2020
    risk 0.32cvss 4.9epss 0.01

    The NuPoint Messenger of Mitel MiCollab before 9.2 could allow an attacker with escalated privilege to access user files due to insufficient access control. Successful exploit could potentially allow an attacker to gain access to sensitive information.

  • CVE-2024-30160MedOct 21, 2024
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a Stored Cross-Site Scripting (XSS) attack due to insufficient validation of user input. A successful…

  • CVE-2024-30159MedOct 21, 2024
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a Stored Cross-Site Scripting (XSS) attack due to insufficient validation of user input. A successful exploit…

  • CVE-2021-32069MedAug 13, 2021
    risk 0.31cvss 4.8epss 0.01

    The AWV component of Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack due to improper TLS negotiation. A successful exploit could allow an attacker to view and modify data.

  • CVE-2021-32068LowAug 13, 2021
    risk 0.24cvss 3.7epss 0.01

    The AWV and MiCollab Client Service components in Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack by sending multiple session renegotiation requests, due to insufficient TLS session controls. A successful exploit could allow an attacker to…

Page 3 of 3