Описание
The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify) user data by injecting arbitrary directory paths due to improper URL validation, aka Directory Traversal.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 9.2 (исключая)
Одно из
cpe:2.3:a:mitel:micollab:*:*:*:*:*:-:*:*
cpe:2.3:a:mitel:micollab:9.2:-:*:*:*:-:*:*
cpe:2.3:a:mitel:micollab:9.2:fp1:*:*:*:-:*:*
EPSS
Процентиль: 53%
0.00304
Низкий
6.5 Medium
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
github
больше 3 лет назад
The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify) user data by injecting arbitrary directory paths due to improper URL validation, aka Directory Traversal.
EPSS
Процентиль: 53%
0.00304
Низкий
6.5 Medium
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-22