Vulnerabilities > Mitel

DATE CVE VULNERABILITY TITLE RISK
2024-10-21 CVE-2024-30157 SQL Injection vulnerability in Mitel Micollab
A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a SQL Injection attack due to insufficient validation of user input.
network
low complexity
mitel CWE-89
7.2
2024-10-21 CVE-2024-30158 SQL Injection vulnerability in Mitel Micollab
A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a SQL Injection attack due to insufficient validation of user input.
network
low complexity
mitel CWE-89
7.2
2024-10-21 CVE-2024-30159 Cross-site Scripting vulnerability in Mitel Micollab
A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a Stored Cross-Site Scripting (XSS) attack due to insufficient validation of user input.
network
low complexity
mitel CWE-79
4.8
2024-10-21 CVE-2024-30160 Cross-site Scripting vulnerability in Mitel Micollab
A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a Stored Cross-Site Scripting (XSS) attack due to insufficient validation of user input.
network
low complexity
mitel CWE-79
4.8
2024-08-13 CVE-2024-36446 Unspecified vulnerability in Mitel Mivoice Mx-One
The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper access control.
network
low complexity
mitel
8.8
2024-06-09 CVE-2024-37569 Command Injection vulnerability in Mitel 6869I SIP Firmware
An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices.
network
low complexity
mitel CWE-77
8.8
2024-06-09 CVE-2024-37570 Command Injection vulnerability in Mitel 6869I SIP Firmware 4.5.0.41
On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (sent by an authenticated user) before appending flags to the busybox ftpget command.
network
low complexity
mitel CWE-77
8.8
2024-02-08 CVE-2023-40265 Unrestricted Upload of File with Dangerous Type vulnerability in Mitel Unify Openscape Xpressions Webassistant
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911.
network
low complexity
mitel CWE-434
8.8
2024-02-08 CVE-2023-40266 Path Traversal vulnerability in Mitel Unify Openscape Xpressions Webassistant
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911.
network
low complexity
mitel CWE-22
critical
9.8
2023-09-14 CVE-2023-39285 Cross-Site Request Forgery (CSRF) vulnerability in Mitel Mivoice Connect
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation.
network
low complexity
mitel CWE-352
4.3