CVE-2021-27401

The Join Meeting page of Mitel MiCollab Web Client before 9.2 FP2 could allow an attacker to access (view and modify) user data by executing arbitrary code due to insufficient input validation, aka Cross-Site Scripting (XSS).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mitel:micollab:*:*:*:*:*:-:*:*
cpe:2.3:a:mitel:micollab:9.2:-:*:*:*:-:*:*
cpe:2.3:a:mitel:micollab:9.2:fp1:*:*:*:-:*:*

History

21 Nov 2024, 05:57

Type Values Removed Values Added
References () https://www.mitel.com/support/security-advisories - Vendor Advisory () https://www.mitel.com/support/security-advisories - Vendor Advisory
References () https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-21-0004 - Vendor Advisory () https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-21-0004 - Vendor Advisory

Information

Published : 2021-08-13 16:15

Updated : 2024-11-21 05:57


NVD link : CVE-2021-27401

Mitre link : CVE-2021-27401

CVE.ORG link : CVE-2021-27401


JSON object : View

Products Affected

mitel

  • micollab
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')