CVE-2021-27402: Path Traversal
The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify) user data by injecting arbitrary directory paths due to improper URL validation, aka Directory Traversal.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27402?
CVE-2021-27402 is a vulnerability in the SAS Admin portal of Mitel MiCollab before 9.2 FP2 that could allow an unauthenticated attacker to access and modify user data by injecting arbitrary directory paths.
How does CVE-2021-27402 impact Mitel MiCollab?
CVE-2021-27402 allows an unauthenticated attacker to view and modify user data through the SAS Admin portal of Mitel MiCollab.
What is the severity of CVE-2021-27402?
CVE-2021-27402 has a severity rating of 6.5 (medium).
How can I fix the vulnerability CVE-2021-27402?
To fix CVE-2021-27402, it is recommended to update Mitel MiCollab to version 9.2 FP2 or later.
Where can I find more information about CVE-2021-27402?
More information about CVE-2021-27402 can be found on the Mitel Security Advisories page: https://www.mitel.com/support/security-advisories