The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to perform a clickjacking attack due to an insecure header response. A successful exploit could allow an attacker to modify the browser header and redirect users.
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-21-0005