Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
3cx 3cx vulnerabilities and exploits
(subscribe to this query)
7.8
CVSSv3
CVE-2019-14935
3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full Control access for Everyone, and leading to privilege escalation because of a StartUp link.
3cx 3cx 15
7.5
CVSSv3
CVE-2022-48482
3CX prior to 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote malicious users to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs.
3cx 3cx
7.5
CVSSv3
CVE-2022-48483
3CX prior to 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote malicious users to read %WINDIR%\system32 files via /Electron/download directory traversal in conjunction with a path component that has a drive letter and uses backslash characters. NOTE: this iss...
3cx 3cx
7.5
CVSSv3
CVE-2019-13176
An issue exists in the 3CX Phone system (web) management console 12.5.44178.1002 up to and including 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST data. There is potential to use this for SSRF (reading local files, outbound HTT...
3cx 3cx 12.5.44178.1002
3cx 3cx 12.5
6.5
CVSSv3
CVE-2021-45491
3CX System through 2022-03-17 stores cleartext passwords in a database.
3cx 3cx
1 Article
6.5
CVSSv3
CVE-2018-7654
On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access to files on the server via path traversal.
3cx 3cx 15.5.6354.2
6.5
CVSSv3
CVE-2017-15359
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/RecordingList/DownloadRecord?file=" and "/api/SupportInfo?file=" are the vulnerable parameters. An attacker must be a...
3cx 3cx 15.5.3554.1
1 EDB exploit
6.1
CVSSv3
CVE-2014-10386
The wp-live-chat-support plugin prior to 4.1.0 for WordPress has JavaScript injections.
3cx Live Chat
6.1
CVSSv3
CVE-2017-18507
The wp-live-chat-support plugin prior to 7.1.05 for WordPress has XSS.
3cx Live Chat
6.1
CVSSv3
CVE-2017-18508
The wp-live-chat-support plugin prior to 7.1.03 for WordPress has XSS.
3cx Live Chat
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
buffer overflow
type confusion
server-side request forgery
CVE-2024-38440
CVE-2024-27801
CVE-2024-5868
CVE-2024-0582
CVE-2024-37643
CVE-2024-3105
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »