Description
A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access non-sensitive user provisioning information and execute arbitrary SQL database commands.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 22 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mitel
Mitel micollab |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:mitel:micollab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mitel
Mitel micollab |
|
| Metrics |
cvssV3_1
|
Mon, 21 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access non-sensitive user provisioning information and execute arbitrary SQL database commands. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-22T17:22:08.377Z
Reserved: 2024-09-22T00:00:00.000Z
Link: CVE-2024-47223
Updated: 2024-10-22T17:21:58.633Z
Status : Analyzed
Published: 2024-10-21T20:15:14.770
Modified: 2025-07-07T17:52:15.770
Link: CVE-2024-47223
No data.
OpenCVE Enrichment
No data.
Weaknesses