← Back to browse · API

CVE-2024-35286

Severity
CRITICAL
CVSS
9.8
EPSS
0.65367
Risk score
62.08
CISA KEV
No
PoC
No
Published
2024-10-21
Modified
2024-12-10
First seen
2026-08-07
Aliases
EUVD-2024-35742, GHSA-89HR-VX2J-R5JV
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-35742

Description

A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.

References