Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rm83-3224-p496

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to insufficient input validation for the session parameter. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts.

A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to insufficient input validation for the session parameter. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts.

EPSS

Процентиль: 76%
0.00937
Низкий

Связанные уязвимости

CVSS3: 9.8
nvd
почти 6 лет назад

A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to insufficient input validation for the session parameter. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts.

EPSS

Процентиль: 76%
0.00937
Низкий