PT-2022-23378 · Mitel · Mitel Micollab
Published
2022-10-25
·
Updated
2022-10-28
·
CVE-2022-36454
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mitel MiCollab versions through 9.5.0.101
Description
A vulnerability in the MiCollab Client API could allow an authenticated attacker to modify their profile parameters due to improper authorization controls. This could allow the attacker to impersonate another user's name.
Recommendations
For versions through 9.5.0.101, update to a version that includes proper authorization controls to prevent profile parameter modification.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mitel Micollab