First published: Thu Apr 25 2019(Updated: )
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the login interface. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel Cmg Suite | <=8.4 | |
Mitel Cmg Suite | =8.4-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18285 is considered a critical vulnerability due to its potential to allow unauthorized access to sensitive database information.
To fix CVE-2018-18285, upgrade Mitel CMG Suite to version 8.4 SP3 or later, where the SQL injection vulnerabilities are addressed.
Mitel CMG Suite versions 8.4 and earlier, including 8.4 SP2, are affected by CVE-2018-18285.
CVE-2018-18285 can lead to data breaches by allowing attackers to execute SQL injection attacks and extract sensitive information from the database.
There are no effective workarounds for CVE-2018-18285; patching the software is the recommended solution.