Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
fusionpbx fusionpbx vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2024-24539
FusionPBX prior to 5.2.0 does not validate a session.
NA
CVE-2024-23387
FusionPBX before 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is logging in to the product.
Fusionpbx Fusionpbx
NA
CVE-2021-43403
An issue exists in FusionPBX prior to 4.5.30. The log_viewer.php Log View page allows an authenticated user to choose an arbitrary filename for download (i.e., not necessarily freeswitch.log in the intended directory).
Fusionpbx Fusionpbx
NA
CVE-2022-35153
FusionPBX 5.0.1 exists to contain a command injection vulnerability via /fax/fax_send.php.
Fusionpbx Fusionpbx 5.0.1
383
VMScore
CVE-2021-37524
Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.26 allows remote unauthenticated users to inject arbitrary web script or HTML via an unsanitized "path" parameter in resources/login.php.
Fusionpbx Fusionpbx
668
VMScore
CVE-2022-28055
Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.
Fusionpbx Fusionpbx
578
VMScore
CVE-2021-43404
An issue exists in FusionPBX prior to 4.5.30. The FAX file name may have risky characters.
Fusionpbx Fusionpbx
578
VMScore
CVE-2021-43405
An issue exists in FusionPBX prior to 4.5.30. The fax_extension may have risky characters (it is not constrained to be numeric).
Fusionpbx Fusionpbx
1 Github repository
578
VMScore
CVE-2021-43406
An issue exists in FusionPBX prior to 4.5.30. The fax_post_size may have risky characters (it is not constrained to preset values).
Fusionpbx Fusionpbx
383
VMScore
CVE-2020-21054
Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "f" variable in app\vars\vars_textarea.php.
Fusionpbx Fusionpbx 4.5.7
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
denial of service
CVE-2024-27371
CVE-2024-20405
CVE-2024-31627
CVE-2024-31625
race condition
CVE-2024-4358
cross-site scripting
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »