CVE-2024-47223: SQL Injection
A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access non-sensitive user provisioning information and execute arbitrary SQL database commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47223?
CVE-2024-47223 is rated as critical due to the potential for unauthenticated SQL injection attacks that can compromise sensitive data.
How do I fix CVE-2024-47223?
To fix CVE-2024-47223, update your Mitel MiCollab software to version 9.8 SP1 FP3 or later.
Who is affected by CVE-2024-47223?
CVE-2024-47223 affects users of Mitel MiCollab versions up to and including 9.8 SP1 FP2 (9.8.1.201).
What type of attack is associated with CVE-2024-47223?
CVE-2024-47223 is associated with a SQL injection attack that exploits insufficient input sanitization.
Can CVE-2024-47223 be exploited remotely?
Yes, an unauthenticated attacker can exploit CVE-2024-47223 remotely due to the nature of SQL injection.