📦 Micollab

by Mitel

🔍 What is Micollab?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-41713

CRITICAL CVSS 9.1 Oct 21, 2024

This vulnerability allows unauthenticated attackers to perform path traversal attacks on Mitel MiCollab's NuPoint Unified Messaging component. Attackers can access, modify, or delete user data and sys...

CVE-2024-35285

CRITICAL CVSS 9.8 Oct 21, 2024

This vulnerability allows unauthenticated attackers to execute arbitrary commands on Mitel MiCollab systems running vulnerable NuPoint Messenger versions. Attackers can exploit insufficient parameter ...

CVE-2024-35314

CRITICAL CVSS 9.8 Oct 21, 2024

This critical vulnerability in Mitel MiCollab Desktop Client and MiVoice Business SVI allows unauthenticated attackers to execute arbitrary commands through command injection. Attackers can exploit in...

CVE-2024-47223

CRITICAL CVSS 9.4 Oct 21, 2024

This critical SQL injection vulnerability in Mitel MiCollab's AWV component allows unauthenticated attackers to execute arbitrary SQL commands. Attackers could access user provisioning information and...

CVE-2021-32071

CRITICAL CVSS 9.8 Aug 13, 2021

CVE-2021-32071 is a critical vulnerability in Mitel MiCollab Client service that allows unauthenticated attackers to bypass access controls. This enables attackers to view and modify application data ...

CVE-2020-35547

CRITICAL CVSS 9.1 Jan 29, 2021

This vulnerability in Mitel MiCollab's NuPoint Messenger allows unauthenticated attackers to view and modify user data through a library index page. It affects organizations using MiCollab versions be...

CVE-2024-30157

HIGH CVSS 7.2 Oct 21, 2024

This vulnerability allows authenticated administrators in Mitel MiCollab to conduct SQL injection attacks due to insufficient input validation. Successful exploitation could enable arbitrary database ...

CVE-2024-47189

HIGH CVSS 7.7 Oct 21, 2024

The Mitel MiCollab AWV component has an SQL injection vulnerability in its API interface that allows unauthenticated attackers to execute arbitrary SQL commands. This affects all MiCollab versions thr...

CVE-2024-41712

MEDIUM CVSS 6.6 Oct 21, 2024

This vulnerability allows authenticated attackers to execute arbitrary commands on Mitel MiCollab systems through command injection in the Web Conferencing Component. Attackers can run commands with t...

CVE-2024-47224

MEDIUM CVSS 6.5 Oct 21, 2024

A CRLF injection vulnerability in Mitel MiCollab AWV component allows unauthenticated attackers to manipulate URLs to conduct phishing attacks. This affects MiCollab versions through 9.8 SP1 FP2 (9.8....

CVE-2024-30159

MEDIUM CVSS 4.8 Oct 21, 2024

This vulnerability allows authenticated administrators in Mitel MiCollab web conferencing to inject malicious scripts that execute in other users' browsers. It affects MiCollab versions through 9.7.1....

CVE-2024-35287

MEDIUM CVSS 6.7 Oct 21, 2024

This vulnerability allows authenticated administrators in Mitel MiCollab's NuPoint Messenger component to escalate privileges and execute arbitrary commands with elevated system rights. It affects MiC...