
Mitel MiCollab 企业协作平台 任意文件读取漏洞(CVE-2024-41713)由于Mitel MiCollab软件的 NuPoint 统一消息 (NPM) 组件中存在身份验证绕过漏洞,并且输入验证不足,未经身份验证的远程攻击者可利用该漏洞执行路径遍历攻击,成功利用可能导致未授权访问、破坏或删除用户的数据和系统配置。影响范围:version < MiCollab 9.8 SP2 (9.8.2.12)
Mitel MiCollab Enterprise Collaboration Platform Arbitrary File Read Vulnerability (CVE-2024-41713) Due to an authentication bypass vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab software, and insufficient input validation, an unauthenticated remote attacker could exploit this vulnerability to perform a path traversal attack. Successful exploitation could lead to unauthorized access, destruction, or deletion of user data and system configurations. Affected versions: version < MiCollab 9.8 SP2 (9.8.2.12)