CVE-2024-30157: SQL Injection
A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a SQL Injection attack due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary database and management operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30157?
CVE-2024-30157 has a high severity rating due to its potential for SQL Injection attacks.
How do I fix CVE-2024-30157?
To fix CVE-2024-30157, update Mitel MiCollab to version 9.7.1.111 or later, which includes patches for this vulnerability.
Who is affected by CVE-2024-30157?
CVE-2024-30157 affects users of Mitel MiCollab versions up to and including 9.7.1.110.
What types of attacks can be performed using CVE-2024-30157?
An authenticated attacker with administrative privileges can perform SQL Injection attacks using CVE-2024-30157.
When was CVE-2024-30157 reported?
CVE-2024-30157 was reported in relation to the Suite Applications Services component of Mitel MiCollab.