First published: Tue Oct 25 2022(Updated: )
A vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload malicious files. A successful exploit could allow an attacker to execute arbitrary code within the context of the application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel MiCollab, MiVoice Business Express | <9.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36452 is a vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 that could allow an unauthenticated attacker to upload malicious files.
An attacker can exploit CVE-2022-36452 by uploading malicious files to the web conferencing component of Mitel MiCollab.
CVE-2022-36452 has a severity rating of critical.
You can check if you are affected by CVE-2022-36452 by verifying the version of Mitel MiCollab you are using (up to version 9.5.0.101) and determining if the web conferencing component is enabled.
To fix CVE-2022-36452, it is recommended to update Mitel MiCollab to version 9.6 or higher and apply any available patches or security updates.