PT-2024-9386 · Mitel · Mitel Micollab+1
Published
2024-05-23
·
Updated
2025-10-12
·
CVE-2024-35286
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mitel MiCollab versions through 9.8.0.33
Description
A flaw exists in the NuPoint Messenger (NPM) component of Mitel MiCollab due to inadequate sanitization of user-supplied data. This allows a remote, unauthenticated attacker to perform a SQL injection attack. Successful exploitation could grant access to sensitive information and enable arbitrary database and management operations. Recent reports indicate that advanced persistent threat (APT) actors have been actively exploiting this and related issues. The vulnerability allows attackers to perform arbitrary file reads.
Recommendations
Update Mitel MiCollab to a version later than 9.8.0.33.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mitel Micollab
Nupoint Messenger