Vulnerabilities > CVE-2023-22854 - Unspecified vulnerability in Mitel Micontact Center Business
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthenticated attacker to download arbitrary files, due to insufficient restriction of URL parameters. A successful exploit could allow access to sensitive information.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |