Arbitrary Script Upload Vulnerability in Mitel MiCollab Web Conferencing Component

Arbitrary Script Upload Vulnerability in Mitel MiCollab Web Conferencing Component

CVE-2022-41326 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code execution within the context of the application.

Learn more about our Web App Pen Testing.