A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access non-sensitive user provisioning information and execute arbitrary SQL database commands.
The vulnerability results from insufficient validation (sanitization) of user-supplied input data in the AWV component. An attacker can submit a specially crafted network request containing malicious SQL fragments, which will be passed directly to the database without proper sanitization. No authentication or user interaction is required.
An attacker can gain access to user provisioning information and execute arbitrary commands in the SQL database, which may lead to data integrity violations and system availability disruption.
Apply patches available from the vendor according to the references — details in Mitel security advisory MISA-2024-0028 available at: https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0028
Mitel MiCollab versions up to and including 9.8 SP1 FP2 (9.8.1.201) — AWV (Audio, Web and Video Conferencing) component.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:HMitel Micollab
APPMitel≤ 9.8.1.201
Related vulnerabilities
Path Traversal w Mitel MiCollab — nieautoryzowany dostęp do danych
Mitel MiCollab/MiVoice TP-240: wyciek danych i DDoS amplifikacja
SQL Injection w Mitel MiCollab NuPoint Messenger — dostęp bez uwierzytelnienia
Command injection w Mitel MiCollab NuPoint Messenger — dostęp bez uwierzytelnienia
Command Injection w Mitel MiCollab i MiVoice Business Solution Virtual Instance