PT-2024-9386 · Mitel · Mitel Micollab+1

Published

2024-05-23

·

Updated

2025-10-12

·

CVE-2024-35286

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mitel MiCollab versions through 9.8.0.33
Description A flaw exists in the NuPoint Messenger (NPM) component of Mitel MiCollab due to inadequate sanitization of user-supplied data. This allows a remote, unauthenticated attacker to perform a SQL injection attack. Successful exploitation could grant access to sensitive information and enable arbitrary database and management operations. Recent reports indicate that advanced persistent threat (APT) actors have been actively exploiting this and related issues. The vulnerability allows attackers to perform arbitrary file reads.
Recommendations Update Mitel MiCollab to a version later than 9.8.0.33.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-11077
CVE-2024-35286

Affected Products

Mitel Micollab
Nupoint Messenger