CVE-2022-36451: SSRF
A vulnerability in the MiCollab Client server component of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to conduct a Server-Side Request Forgery (SSRF) attack due to insufficient restriction of URL parameters. A successful exploit could allow an attacker to leverage connections and permissions available to the host server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36451?
The severity of CVE-2022-36451 is high with a score of 8.8.
How can an authenticated attacker exploit CVE-2022-36451?
An authenticated attacker can exploit CVE-2022-36451 by conducting a Server-Side Request Forgery (SSRF) attack due to insufficient restriction of URL parameters.
What is the affected software for CVE-2022-36451?
The affected software for CVE-2022-36451 is Mitel MiCollab through version 9.5.0.101.
Where can I find more information about CVE-2022-36451?
You can find more information about CVE-2022-36451 on Mitel's official support page or the Mitel Product Security Advisory 22-0006.
What is the CWE (Common Weakness Enumeration) ID for CVE-2022-36451?
The CWE ID for CVE-2022-36451 is 918.