First published: Mon Feb 13 2023(Updated: )
The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthenticated attacker to download arbitrary files, due to insufficient restriction of URL parameters. A successful exploit could allow access to sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel MiContact Center Business | >=9.2.2.0<9.4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-22854.
The severity level of CVE-2023-22854 is high with a severity value of 7.5.
The affected software for CVE-2023-22854 is Mitel MiContact Center Business server versions 9.2.2.0 through 9.4.1.0.
An unauthenticated attacker could download arbitrary files and gain access to sensitive information.
To fix CVE-2023-22854, it is recommended to update Mitel MiContact Center Business server to version 9.4.2.0 or higher.