CVE-2024-35286: SQL Injection
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35286?
CVE-2024-35286 has a high severity rating due to the potential for SQL injection attacks that could expose sensitive information.
How do I fix CVE-2024-35286?
To fix CVE-2024-35286, it is recommended to update Mitel NuPoint Messenger to version 9.8.0.34 or later.
Who is affected by CVE-2024-35286?
CVE-2024-35286 affects users of Mitel NuPoint Messenger versions up to 9.8.0.33.
What type of attack does CVE-2024-35286 allow?
CVE-2024-35286 allows unauthenticated attackers to conduct SQL injection attacks due to insufficient input sanitization.
What could an attacker gain by exploiting CVE-2024-35286?
An attacker exploiting CVE-2024-35286 could access sensitive information and execute arbitrary database commands.