PT-2020-12854 · Mitel · Mitel Micollab Awv
Tri Bui
·
Published
2020-06-10
·
Updated
2023-04-06
·
CVE-2020-11798
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mitel MiCollab AWV versions prior to 8.1.2.4
Mitel MiCollab AWV versions 9.x prior to 9.1.3
Description
A Directory Traversal issue in the web conference component could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.
Recommendations
For versions prior to 8.1.2.4, update to version 8.1.2.4 or later.
For versions 9.x prior to 9.1.3, update to version 9.1.3 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mitel Micollab Awv