Unauthenticated SQL Injection Vulnerability in Mitel MiCollab's API Interface
CVE-2024-47189
7.7HIGH
What is CVE-2024-47189?
The API Interface of the Mitel MiCollab component, particularly in versions up to 9.8 SP1 FP2, is vulnerable to SQL injection attacks. This vulnerability arises from inadequate sanitization of user-provided input, which can be exploited by an unauthenticated attacker. Successful exploitation allows access to user provisioning information and the execution of arbitrary SQL commands, potentially compromising system integrity.