CVE-2020-11798
Summary
| CVE | CVE-2020-11798 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-10 18:15:00 UTC |
| Updated | 2023-04-06 17:15:00 UTC |
| Description | A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mitel | Micollab Audio Web Video Conferencing | All | All | All | All |
| Application | Mitel | Micollab Audio Web Video Conferencing | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mitel Product Security Advisory 20-0005 | CONFIRM | www.mitel.com | Vendor Advisory |
| Mitel MiCollab AWV 8.1.2.4 / 9.1.3 Directory Traversal / LFI ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Attention Required! | Cloudflare | CONFIRM | www.mitel.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.