PT-2024-7462 · Mitel · Mitel Micollab

Patrick Webster

·

Published

2024-10-09

·

Updated

2025-06-24

·

CVE-2024-47224

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions: Mitel MiCollab versions prior to 9.8 SP1 FP2 (9.8.1.201)
Description: A vulnerability in the AWV component of Mitel MiCollab could allow an unauthenticated attacker to conduct a CRLF injection attack due to inadequate encoding of user input in URLs. This could enable an attacker to perform a phishing attack by redirecting users to an untrusted site using a specially crafted link.
Recommendations: For Mitel MiCollab versions prior to 9.8 SP1 FP2 (9.8.1.201), update to a version that includes the fix for this issue to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Encoding or Escaping of Output

Open Redirect

Weakness Enumeration

Related Identifiers

BDU:2024-08842
CVE-2024-47224

Affected Products

Mitel Micollab