First published: Fri Apr 14 2023(Updated: )
A vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shared file via a crafted request - including the exact path and filename - due to improper authentication control. A successful exploit could allow access to sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel MiCollab, MiVoice Business Express | <9.7 | |
Mitel MiCollab | <9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25597 is a vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 that could allow an unauthenticated attacker to download a shared file via a crafted request.
An attacker can exploit CVE-2023-25597 by sending a crafted request to the web conferencing component of Mitel MiCollab, allowing them to download a shared file.
CVE-2023-25597 has a severity rating of medium.
CVE-2023-25597 affects Mitel MiCollab versions up to and including 9.6.2.9.
Yes, it is recommended to upgrade to a version of Mitel MiCollab that is not affected by CVE-2023-25597.