The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to view sensitive system information through an HTTP response due to insufficient output sanitization.
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
Link | Tags |
---|---|
https://www.mitel.com/support/security-advisories | vendor advisory |
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-21-0005 | vendor advisory |