CVE-2022-41223
Description
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.
Summary dbcve.org
The Director database component of Mitel MiVoice Connect versions through 19.3 (22.22.6100.0) contains a code-injection vulnerability due to insufficient restrictions on database data types. An authenticated attacker can inject malicious code through crafted data inputs processed by the database component.
Mitigation
Apply the vendor patch (release 22.22.6100.0 or later) to remediate the data type validation weakness in the Director database component. If immediate patching is not possible, restrict database component access to trusted authenticated users only.