CVE-2022-36452: Malicious File Upload
A vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload malicious files. A successful exploit could allow an attacker to execute arbitrary code within the context of the application.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-36452?
CVE-2022-36452 is a vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 that could allow an unauthenticated attacker to upload malicious files.
How can an attacker exploit CVE-2022-36452?
An attacker can exploit CVE-2022-36452 by uploading malicious files to the web conferencing component of Mitel MiCollab.
What is the severity of CVE-2022-36452?
CVE-2022-36452 has a severity rating of critical.
How can I check if I am affected by CVE-2022-36452?
You can check if you are affected by CVE-2022-36452 by verifying the version of Mitel MiCollab you are using (up to version 9.5.0.101) and determining if the web conferencing component is enabled.
How can I fix CVE-2022-36452?
To fix CVE-2022-36452, it is recommended to update Mitel MiCollab to version 9.6 or higher and apply any available patches or security updates.