First published: Mon Oct 21 2024(Updated: )
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel NuPoint Messenger | <9.8.0.33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35286 has a high severity rating due to the potential for SQL injection attacks that could expose sensitive information.
To fix CVE-2024-35286, it is recommended to update Mitel NuPoint Messenger to version 9.8.0.34 or later.
CVE-2024-35286 affects users of Mitel NuPoint Messenger versions up to 9.8.0.33.
CVE-2024-35286 allows unauthenticated attackers to conduct SQL injection attacks due to insufficient input sanitization.
An attacker exploiting CVE-2024-35286 could access sensitive information and execute arbitrary database commands.