A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and previous versions, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and previous versions, could allow an unauthenticated malicious user to conduct an SQL injection attack due to insufficient input validation for the signin interface. A successful exploit could allow an malicious user to extract sensitive information from the database.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mitel st 14.2 |
||
mitel mivoice connect |