The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code execution within the context of the application.
References
Link | Resource |
---|---|
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0009 | Mitigation Vendor Advisory |
https://www.mitel.com/support/security-advisories | Vendor Advisory |
Configurations
Information
Published : 2022-11-21 17:15
Updated : 2022-11-25 19:26
NVD link : CVE-2022-41326
Mitre link : CVE-2022-41326
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
mitel
- micollab