PT-2024-7462 · Mitel · Mitel Micollab
Patrick Webster
·
Published
2024-10-09
·
Updated
2025-06-24
·
CVE-2024-47224
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions:
Mitel MiCollab versions prior to 9.8 SP1 FP2 (9.8.1.201)
Description:
A vulnerability in the AWV component of Mitel MiCollab could allow an unauthenticated attacker to conduct a CRLF injection attack due to inadequate encoding of user input in URLs. This could enable an attacker to perform a phishing attack by redirecting users to an untrusted site using a specially crafted link.
Recommendations:
For Mitel MiCollab versions prior to 9.8 SP1 FP2 (9.8.1.201), update to a version that includes the fix for this issue to prevent exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Encoding or Escaping of Output
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mitel Micollab