Vulnerabilities > Mitel > CMG Suite > High

DATE CVE VULNERABILITY TITLE RISK
2019-04-25 CVE-2018-18285 SQL Injection vulnerability in Mitel CMG Suite 8.4
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the login interface.
network
low complexity
mitel CWE-89
7.5
2019-04-25 CVE-2018-18286 SQL Injection vulnerability in Mitel CMG Suite 8.4
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the changepwd interface.
network
low complexity
mitel CWE-89
7.5