SQL Injection Vulnerability in Mitel MiCollab Services
CVE-2025-52914

8.8HIGH

Key Information:

Vendor

Mitel

Vendor
CVE Published:
8 August 2025

What is CVE-2025-52914?

A vulnerability exists within the Suite Applications Services of Mitel MiCollab versions 10.0 to 10.0.1.101, allowing authenticated attackers to perform SQL Injection attacks. This issue arises from inadequate validation of user input, enabling potential attackers to execute arbitrary SQL commands on the database, leading to unauthorized data access and manipulation. It is imperative for users to evaluate their systems and apply the recommended security measures to safeguard against this type of threat.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.