CVE-2021-27402

MEDIUM

Mitel MiCollab <9.2 FP2 - Path Traversal

Title source: llm
STIX 2.1

Description

The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify) user data by injecting arbitrary directory paths due to improper URL validation, aka Directory Traversal.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0107
EPSS Percentile 60.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-22
Status published
Products (2)
mitel/micollab 9.2 (2 CPE variants)
mitel/micollab < 9.2
Published Aug 13, 2021
Tracked Since Feb 18, 2026