CVE-2021-27402

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
13/08/2021
Last modified:
23/08/2021

Description

The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify) user data by injecting arbitrary directory paths due to improper URL validation, aka Directory Traversal.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mitel:micollab:*:*:*:*:*:-:*:* 9.2 (excluding)
cpe:2.3:a:mitel:micollab:9.2:-:*:*:*:-:*:*
cpe:2.3:a:mitel:micollab:9.2:fp1:*:*:*:-:*:*