CVE-2018-18819 Information

Description

A vulnerability in the web conference chat component of MiCollab versions 7.3 PR6 (7.3.0.601) and earlier and 8.0 (8.0.0.40) through 8.0 SP2 FP2 (8.0.2.202) and MiVoice Business Express versions 7.3 PR3 (7.3.1.302) and earlier and 8.0 (8.0.0.40) through 8.0 SP2 FP1 (8.0.2.202) could allow creation of unauthorized chat sessions due to insufficient access controls. A successful exploit could allow execution of arbitrary commands.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Reference

https://www.mitel.com/support/security-advisories https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-18-0012

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

5.3

Share on: