CVE-2024-41713

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
21/10/2024
Last modified:
04/11/2025

Description

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mitel:micollab:*:*:*:*:*:-:*:* 9.8.1.201 (including)