SQL injection in MiCollab and MiVoice Business Solution Virtual Instance (MiVB SVI) - #VU134877
Published: June 18, 2026
MiCollab
MiVoice Business Solution Virtual Instance (MiVB SVI)
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary SQL database commands.
The vulnerability exists due to insufficient validation of user input in the Audio, Web, and Video Conferencing (AWV) component when handling requests. A remote attacker can send a specially crafted request to execute arbitrary SQL database commands.