CVE-2024-35286
Mitel MiCollab NuPoint Messenger (NPM) SQL Injection Vulnerability
Record summary
CVE-2024-35286 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 10, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 6, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
MiCollabBrowse Mitel / MiCollabDefault status: unknown | VulnCheck, CVE List | Through 9.8.0.33 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALMitel MiCollab <= 9.8.0.33 - SQL InjectionCVSS 9.8
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.
Impact
Unauthenticated attackers can execute arbitrary SQL queries to access sensitive information and execute arbitrary database and management operations.
Remediation
Update Mitel MiCollab to a version later than 9.8.0.33.
Source: ProjectDiscovery