A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.
https://thehackernews.com/2025/01/cisa-flags-critical-flaws-in-mitel-and.html
https://www.helpnetsecurity.com/2024/12/05/mitel-micollab-zero-day-and-poc-exploit-unveiled/
https://www.darkreading.com/vulnerabilities-threats/bypass-bug-critical-n-day-mitel-micollab
https://thehackernews.com/2024/12/critical-mitel-micollab-flaw-exposes.html