Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-25597


A vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shared file via a crafted request - including the exact path and filename - due to improper authentication control. A successful exploit could allow access to sensitive information.


Published

2023-04-14T21:15:08.153

Last Modified

2025-02-07T22:15:11.907

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-287
  • Type: Secondary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mitel micollab < 9.7 Yes

References