The API Interface of the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct SQL injection due to insufficient sanitization of user input. A successful exploit could allow an attacker with knowledge of specific details to access non-sensitive user provisioning information and execute arbitrary SQL database commands.
Metrics
Affected Vendors & Products
References
History
Mon, 04 Nov 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-89 | |
Metrics |
cvssV3_1
|
Tue, 22 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 21 Oct 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The API Interface of the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct SQL injection due to insufficient sanitization of user input. A successful exploit could allow an attacker with knowledge of specific details to access non-sensitive user provisioning information and execute arbitrary SQL database commands. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-10-21T00:00:00
Updated: 2024-11-04T21:50:17.150Z
Reserved: 2024-09-20T00:00:00
Link: CVE-2024-47189
Vulnrichment
Updated: 2024-10-22T17:33:49.910Z
NVD
Status : Awaiting Analysis
Published: 2024-10-21T20:15:14.697
Modified: 2024-11-04T22:35:09.220
Link: CVE-2024-47189
Redhat
No data.