Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 27.00 |
| Exploitation signal(KEV listed) | ×1.50 |
| Ransomware bonus | +5.00 |
| VPI | 45.50 |
VPI formula vpi-v1
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.