Show filters
41 Total Results
Displaying 21-30 of 41
Sort by:
Attacker Value
Unknown

CVE-2021-27402

Disclosure Date: August 13, 2021 (last updated February 23, 2025)
The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify) user data by injecting arbitrary directory paths due to improper URL validation, aka Directory Traversal.
Attacker Value
Unknown

CVE-2021-32070

Disclosure Date: August 13, 2021 (last updated February 23, 2025)
The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to perform a clickjacking attack due to an insecure header response. A successful exploit could allow an attacker to modify the browser header and redirect users.
Attacker Value
Unknown

CVE-2020-35547

Disclosure Date: January 29, 2021 (last updated November 28, 2024)
A library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 could allow an unauthenticated attacker to gain access (view and modify) to user data.
Attacker Value
Unknown

CVE-2020-25608

Disclosure Date: December 18, 2020 (last updated February 22, 2025)
The SAS portal of Mitel MiCollab before 9.2 could allow an attacker to access user credentials due to improper input validation, aka SQL Injection.
Attacker Value
Unknown

CVE-2020-27340

Disclosure Date: December 18, 2020 (last updated November 28, 2024)
The online help portal of Mitel MiCollab before 9.2 could allow an attacker to redirect a user to an unauthorized website by executing malicious script due to insufficient access control.
Attacker Value
Unknown

CVE-2020-25610

Disclosure Date: December 18, 2020 (last updated November 28, 2024)
The AWV component of Mitel MiCollab before 9.2 could allow an attacker to gain access to a web conference due to insufficient access control for conference codes.
Attacker Value
Unknown

CVE-2020-25612

Disclosure Date: December 18, 2020 (last updated November 28, 2024)
The NuPoint Messenger of Mitel MiCollab before 9.2 could allow an attacker with escalated privilege to access user files due to insufficient access control. Successful exploit could potentially allow an attacker to gain access to sensitive information.
Attacker Value
Unknown

CVE-2020-25609

Disclosure Date: December 18, 2020 (last updated February 22, 2025)
The NuPoint Messenger Portal of Mitel MiCollab before 9.2 could allow an authenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to view and modify user data.
Attacker Value
Unknown

CVE-2020-25606

Disclosure Date: December 18, 2020 (last updated February 22, 2025)
The AWV component of Mitel MiCollab before 9.2 could allow an attacker to view system information by sending arbitrary code due to improper input validation, aka XSS.
Attacker Value
Unknown

CVE-2020-25611

Disclosure Date: December 18, 2020 (last updated February 22, 2025)
The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending arbitrary code due to improper input validation, aka XSS. Successful exploitation could allow an attacker to view user conference information.