The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.
2022-11-22T01:15:32.897
2025-02-07T14:53:04.327
Analyzed
CVSSv3.1: 6.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mitel | mivoice_connect | < 19.3 | Yes |
Application | mitel | mivoice_connect | 19.3 | Yes |