CVE Vulnerabilities

CVE-2023-22854

Published: Feb 13, 2023 | Modified: Mar 21, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthenticated attacker to download arbitrary files, due to insufficient restriction of URL parameters. A successful exploit could allow access to sensitive information.

Affected Software

NameVendorStart VersionEnd Version
Micontact_center_businessMitel9.2.2.0 (including)9.4.2.0 (excluding)

References