CVE-2020-27340Open Redirect in Micollab

CWE-601Open Redirect3 documents3 sources
Severity
6.1MEDIUMNVD
EPSS
0.3%
top 47.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 18
Latest updateMay 24

Description

The online help portal of Mitel MiCollab before 9.2 could allow an attacker to redirect a user to an unauthorized website by executing malicious script due to insufficient access control.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:LExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDmitel/micollab< 9.2

🔴Vulnerability Details

2
GHSA
GHSA-hmm3-wj4g-8w8g: The online help portal of Mitel MiCollab before 92022-05-24
CVEList
CVE-2020-27340: The online help portal of Mitel MiCollab before 92020-12-18
CVE-2020-27340 — Open Redirect in Mitel Micollab | cvebase