Show filters
114 Total Results
Displaying 71-80 of 114
Sort by:
Attacker Value
Unknown

CVE-2020-24593

Disclosure Date: September 25, 2020 (last updated February 22, 2025)
Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation.
Attacker Value
Unknown

CVE-2020-24595

Disclosure Date: September 25, 2020 (last updated November 28, 2024)
Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to retrieve sensitive information due to insufficient access control.
Attacker Value
Unknown

CVE-2020-24692

Disclosure Date: September 25, 2020 (last updated February 22, 2025)
The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain access to a user session.
Attacker Value
Unknown

CVE-2020-11797

Disclosure Date: August 26, 2020 (last updated November 28, 2024)
An Authentication Bypass vulnerability in the Published Area of the web conferencing component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an unauthenticated attacker to gain access to unauthorized information due to insufficient access validation. A successful exploit could allow an attacker to access sensitive shared files.
Attacker Value
Unknown

CVE-2020-12456

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
A remote code execution vulnerability in Mitel MiVoice Connect Client before 214.100.1223.0 could allow an attacker to execute arbitrary code in the chat notification window, due to improper rendering of chat messages. A successful exploit could allow an attacker to steal session cookies, perform directory traversal, and execute arbitrary scripts in the context of the Connect client.
Attacker Value
Unknown

CVE-2020-13863

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
The SAS portal of Mitel MiCollab before 9.1.3 could allow an attacker to access user data by performing a header injection in HTTP responses, due to the improper handling of input parameters. A successful exploit could allow an attacker to access user information.
Attacker Value
Unknown

CVE-2020-13617

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.
Attacker Value
Unknown

CVE-2020-13767

Disclosure Date: August 26, 2020 (last updated November 28, 2024)
The Mitel MiCollab application before 9.1.332 for iOS could allow an unauthorized user to access restricted files and folders due to insufficient access control. An exploit requires a rooted iOS device, and (if successful) could allow an attacker to gain access to sensitive information,
Attacker Value
Unknown

CVE-2020-11798

Disclosure Date: June 10, 2020 (last updated February 21, 2025)
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.
Attacker Value
Unknown

CVE-2020-12679

Disclosure Date: May 07, 2020 (last updated February 21, 2025)
A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 allows remote attackers to inject arbitrary JavaScript and HTML via the PATH_INFO to home.php.