目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-52914 PoC — Mitel MiCollab SQL注入漏洞

来源
关联漏洞
标题: Mitel MiCollab SQL注入漏洞 (CVE-2025-52914)
Description:Mitel MiCollab是加拿大敏迪(Mitel)公司的一款为员工提供语音、视频、消息、音频会议和团队协作的移动应用程序。 Mitel MiCollab 10.0.1.101及之前版本存在SQL注入漏洞,该漏洞源于Suite Applications Services组件输入验证不足,可能导致SQL注入攻击。
Description
Detection for CVE-2025-52914
介绍
# CVE-2025-52914

## How does this detection method work?

Versions are extracted from target hosts, specifically the `SVR_VER` html response in the body, and then matches on versions prior to 9.3.1 and versions from 10.0.26 to 10.1.101 (inclusive).

## How do I run this script?

1. Download Nuclei from [here](https://github.com/projectdiscovery/nuclei)
2. Copy the template to your local system
3. Run the following command: `nuclei -u https://yourHost.com -t template.yaml` 

## References

- https://nvd.nist.gov/vuln/detail/CVE-2025-52914
- https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2025-0008


## Disclaimer

Use at your own risk, I will not be responsible for illegal activities you conduct on infrastructure you do not own or have permission to scan.

## Contact

Feel free to reach out to me on [Signal](https://signal.me/#eu/0Qd68U1ivXNdWCF4hf70UYFo7tB0w-GQqFpYcyV6-yr4exn2SclB6bFeP7wTAxQw) if you have any questions.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →