First published: Fri Jan 29 2021(Updated: )
A library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 could allow an unauthenticated attacker to gain access (view and modify) to user data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel MiCollab, MiVoice Business Express | <=9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35547 is a vulnerability in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 that could allow an unauthenticated attacker to gain access and modify user data.
CVE-2020-35547 has a severity rating of 9.1, which is classified as critical.
Mitel MiCollab versions up to and including 9.2 are affected by CVE-2020-35547.
An attacker can exploit CVE-2020-35547 by accessing the library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 without authentication, allowing them to view and modify user data.
You can find more information about CVE-2020-35547 in the Mitel Security Advisories at the following links: [Link 1](https://www.mitel.com/support/security-advisories), [Link 2](https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-20-0016).