PT-2021-17441 · Mitel · Mitel Micollab

Published

2021-08-13

·

Updated

2021-08-23

·

CVE-2021-27402

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mitel MiCollab versions prior to 9.2 FP2
Description The issue allows an unauthenticated attacker to access and modify user data by injecting arbitrary directory paths due to improper URL validation, also known as Directory Traversal. This enables the attacker to view and modify user data without proper authentication.
Recommendations For versions prior to 9.2 FP2, update to version 9.2 FP2 or later to resolve the issue. As a temporary workaround, consider restricting access to the SAS Admin portal to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27402

Affected Products

Mitel Micollab