EUVD-2022-44464
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 21 Feb 2023. Evidence sources: cisa_kev.
- ENISA score
- 6.8 · CVSS 3.1
- Advisory evidence
- 1 linked advisory record
