CVE-2021-32070: Medium severity mitel micollab, mivoice business express vulnerability
The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to perform a clickjacking attack due to an insecure header response. A successful exploit could allow an attacker to modify the browser header and redirect users.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32070?
CVE-2021-32070 is a vulnerability in the MiCollab Client Service component in Mitel MiCollab before 9.3 that could allow an attacker to perform a clickjacking attack.
What is the severity of CVE-2021-32070?
The severity of CVE-2021-32070 is medium with a CVSS score of 5.4.
How does CVE-2021-32070 work?
CVE-2021-32070 works by exploiting an insecure header response in the MiCollab Client Service component, allowing an attacker to modify the browser header and redirect users.
Which versions of Mitel MiCollab are affected by CVE-2021-32070?
Mitel MiCollab versions up to, but excluding, version 9.3 are affected by CVE-2021-32070.
How can CVE-2021-32070 be fixed?
To fix CVE-2021-32070, users should update to Mitel MiCollab version 9.3 or later.