Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2023-22854
Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthenticated attacker to download arbitrary files, due to insufficient restriction of URL parameters. A successful exploit could allow access to sensitive information.
0
Attacker Value
Unknown
CVE-2021-3352
Disclosure Date: August 13, 2021 (last updated November 28, 2024)
The Software Development Kit in Mitel MiContact Center Business from 8.0.0.0 through 8.1.4.1 and 9.0.0.0 through 9.3.1.0 could allow an unauthenticated attacker to access (view and modify) user data without authorization due to improper handling of tokens.
0
Attacker Value
Unknown
CVE-2020-24693
Disclosure Date: December 18, 2020 (last updated November 28, 2024)
The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow a local attacker to view system information due to insufficient output sanitization.
0
Attacker Value
Unknown
CVE-2020-24692
Disclosure Date: September 25, 2020 (last updated February 22, 2025)
The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain access to a user session.
0
Attacker Value
Unknown
CVE-2020-9379
Disclosure Date: February 25, 2020 (last updated November 27, 2024)
The Software Development Kit of the MiContact Center Business with Site Based Security 8.0 through 9.0.1.0 before KB496276 allows an authenticated user to access sensitive information. A successful exploit could allow unauthorized access to user conversations.
0