CVE-2024-35286 is a critical SQL injection vulnerability in Mitel MiCollab through version 9.8.0.33, specifically affecting the NuPoint Messenger (NPM) component. An unauthenticated attacker can exploit this flaw due to insufficient user input sanitization, potentially gaining access to sensitive information and executing arbitrary database and management operations. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, this vulnerability presents a significant risk. While not yet in the KEV catalog, public proof-of-concept exploits exist via Nuclei templates, and it has garnered substantial community discussion and media coverage, including reports of a zero-day flaw and authentication bypass.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.8.0.33CPE matchmatch criteria | cpe:2.3:a:mitel:micollab:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.