← Back

CVE-2018-18819

nvd nist
Published: Nov 12, 2019Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP2 (8.0.2.202), and MiVoice Business Express versions 7.3 PR3 (7.3.1.302) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP1 (8.0.2.202), could allow creation of unauthorized chat sessions, due to insufficient access controls. A successful exploit could allow execution of arbitrary commands.

Affected (4)

2 products
Micollab
Mivoice Business Express
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Mitel
From 7.3 to 7.3.0.601
From 8.0.0.40 to 8.0.2.202
Mitel
From 7.0 to 7.3.1.302
From 8.0.0.40 to 8.0.2.202

References (4)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.