First published: Mon Oct 21 2024(Updated: )
A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a SQL Injection attack due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary database and management operations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel MiCollab | <=9.7.1.110 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30157 has a high severity rating due to its potential for SQL Injection attacks.
To fix CVE-2024-30157, update Mitel MiCollab to version 9.7.1.111 or later, which includes patches for this vulnerability.
CVE-2024-30157 affects users of Mitel MiCollab versions up to and including 9.7.1.110.
An authenticated attacker with administrative privileges can perform SQL Injection attacks using CVE-2024-30157.
CVE-2024-30157 was reported in relation to the Suite Applications Services component of Mitel MiCollab.