CVE-2021-27401

The Join Meeting page of Mitel MiCollab Web Client before 9.2 FP2 could allow an attacker to access (view and modify) user data by executing arbitrary code due to insufficient input validation, aka Cross-Site Scripting (XSS).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mitel:micollab:*:*:*:*:*:-:*:*
cpe:2.3:a:mitel:micollab:9.2:-:*:*:*:-:*:*
cpe:2.3:a:mitel:micollab:9.2:fp1:*:*:*:-:*:*

History

23 Aug 2021, 19:06

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.1
References (CONFIRM) https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-21-0004 - (CONFIRM) https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-21-0004 - Vendor Advisory
References (MISC) https://www.mitel.com/support/security-advisories - (MISC) https://www.mitel.com/support/security-advisories - Vendor Advisory
CPE cpe:2.3:a:mitel:micollab:9.2:-:*:*:*:-:*:*
cpe:2.3:a:mitel:micollab:*:*:*:*:*:-:*:*
cpe:2.3:a:mitel:micollab:9.2:fp1:*:*:*:-:*:*

13 Aug 2021, 16:24

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-13 16:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-27401

Mitre link : CVE-2021-27401

CVE.ORG link : CVE-2021-27401


JSON object : View

Products Affected

mitel

  • micollab
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')