Vulnerability Details CVE-2022-36453
A vulnerability in the MiCollab Client API of Mitel MiCollab 9.1.3 through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper authorization controls. A successful exploit could allow the authenticated attacker to control another extension number.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 39.9%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2022-36453
-
cpe:2.3:a:mitel:micollab:9.1.204
-
cpe:2.3:a:mitel:micollab:9.1.205
-
cpe:2.3:a:mitel:micollab:9.1.3
-
cpe:2.3:a:mitel:micollab:9.1.311
-
cpe:2.3:a:mitel:micollab:9.1.312
-
cpe:2.3:a:mitel:micollab:9.1.313
-
cpe:2.3:a:mitel:micollab:9.1.332
-
cpe:2.3:a:mitel:micollab:9.1.8
-
cpe:2.3:a:mitel:micollab:9.2
-
cpe:2.3:a:mitel:micollab:9.3
-
cpe:2.3:a:mitel:micollab:9.4
-
cpe:2.3:a:mitel:micollab:9.5.0.101