CVE-2018-18285

CRITICAL

Mitel CMG Suite < 8.4 SP2 - Unauthenticated SQL Injection via Login Interface

Title source: llm
STIX 2.1

Description

SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the login interface. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts.

Scores

CVSS v3 9.8
EPSS 0.0184
EPSS Percentile 76.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (2)
mitel/cmg_suite 8.4 sp2
mitel/cmg_suite < 8.4
Published Apr 25, 2019
Tracked Since Feb 18, 2026