Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
fusionpbx fusionpbx vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2022-28055
Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.
Fusionpbx Fusionpbx
NA
CVE-2021-43403
An issue exists in FusionPBX prior to 4.5.30. The log_viewer.php Log View page allows an authenticated user to choose an arbitrary filename for download (i.e., not necessarily freeswitch.log in the intended directory).
Fusionpbx Fusionpbx
6.5
CVSSv2
CVE-2021-43404
An issue exists in FusionPBX prior to 4.5.30. The FAX file name may have risky characters.
Fusionpbx Fusionpbx
6.5
CVSSv2
CVE-2021-43405
An issue exists in FusionPBX prior to 4.5.30. The fax_extension may have risky characters (it is not constrained to be numeric).
Fusionpbx Fusionpbx
1 Github repository
6.5
CVSSv2
CVE-2021-43406
An issue exists in FusionPBX prior to 4.5.30. The fax_post_size may have risky characters (it is not constrained to preset values).
Fusionpbx Fusionpbx
9
CVSSv2
CVE-2019-16965
resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative malicious users to execute any commands on the host as www-data.
Fusionpbx Fusionpbx
4.3
CVSSv2
CVE-2019-16968
An issue exists in FusionPBX up to 4.5.7. In the file app\conference_controls\conference_control_details.php, an unsanitized id variable coming from the URL is reflected in HTML on 2 occasions, leading to XSS.
Fusionpbx Fusionpbx
4.3
CVSSv2
CVE-2019-16969
In FusionPBX up to 4.5.7, the file app\fifo_list\fifo_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.
Fusionpbx Fusionpbx
4.3
CVSSv2
CVE-2019-16971
In FusionPBX up to 4.5.7, the file app\messages\messages_thread.php uses an unsanitized "contact_uuid" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.
Fusionpbx Fusionpbx
4.3
CVSSv2
CVE-2019-16976
In FusionPBX up to 4.5.7, the file app\destinations\destination_imports.php uses an unsanitized "query_string" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.
Fusionpbx Fusionpbx
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-36920
buffer overflow
CVE-2024-36913
CVE-2024-5497
CVE-2024-23917
CVE-2024-4956
server-side request forgery
CVE-2024-35468
SSTI
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »