A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit requires user interaction and could allow an attacker to execute arbitrary scripts.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-10-21 21:15
Updated : 2025-07-07 17:54
NVD link : CVE-2024-35314
Mitre link : CVE-2024-35314
CVE.ORG link : CVE-2024-35314
JSON object : View
Products Affected
mitel
- mivoice_business_solution_virtual_instance
- micollab
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
