PT-2022-23378 · Mitel · Mitel Micollab

Published

2022-10-25

·

Updated

2022-10-28

·

CVE-2022-36454

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mitel MiCollab versions through 9.5.0.101
Description A vulnerability in the MiCollab Client API could allow an authenticated attacker to modify their profile parameters due to improper authorization controls. This could allow the attacker to impersonate another user's name.
Recommendations For versions through 9.5.0.101, update to a version that includes proper authorization controls to prevent profile parameter modification. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-36454

Affected Products

Mitel Micollab