Record summary

CVE-2024-35286 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 10, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 6, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

VulnCheck, CVE ListThrough 9.8.0.33affected

Nuclei templates

1
ProjectDiscoveryCRITICALMitel MiCollab <= 9.8.0.33 - SQL InjectionCVSS 9.8

A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.

Impact

Unauthenticated attackers can execute arbitrary SQL queries to access sensitive information and execute arbitrary database and management operations.

Remediation

Update Mitel MiCollab to a version later than 9.8.0.33.

WeaknessesCWE-89
Authorsdaffainfo
Template tagscvecve2024mitelmicollabsqlivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:mitel:micollab:*:*:*:*:*:*:*:*
Shodan: html:"Mitel" html:"MiCollab"

Source: ProjectDiscovery

References

2