CVE-2020-11798
Mitel micollab_audio\,_web_\&_video_conferencing Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2020-11798 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
micollab_audio\,_web_\&_video_conferencingBrowse Mitel / micollab_audio\,_web_\&_video_conferencing | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBMitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal and LFIExploitDB exploitby Kahvi-0Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMMitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory TraversalCVSS 5.3
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.
Impact
An attacker can exploit this vulnerability to view, modify, or delete arbitrary files on the system, potentially leading to unauthorized access or data leakage.
Remediation
Apply the latest security patches or updates provided by Mitel to mitigate the vulnerability and prevent unauthorized access.
Source: ProjectDiscovery