Directory Traversal Vulnerability in Mitel MiCollab Admin Portal
CVE-2021-27402
6.5MEDIUM
Summary
The SAS Admin portal of Mitel MiCollab prior to version 9.2 FP2 is susceptible to a directory traversal vulnerability. This flaw allows an unauthenticated attacker to potentially access and modify user data by exploiting improper URL validation mechanisms, thereby injecting arbitrary directory paths. This vulnerability raises significant security concerns as it can lead to unauthorized exposure and alteration of sensitive information.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved