Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
fusionpbx vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2019-16988
In FusionPBX up to v4.5.7, the file app\basic_operator_panel\resources\content.php uses an unsanitized "eavesdrop_dest" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.
Fusionpbx Fusionpbx
4
CVSSv2
CVE-2019-16990
In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takes any pathname (base64 encoded) and allows a download of it.
Fusionpbx Fusionpbx
NA
CVE-2024-23387
FusionPBX before 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is logging in to the product.
Fusionpbx Fusionpbx
NA
CVE-2021-43403
An issue exists in FusionPBX prior to 4.5.30. The log_viewer.php Log View page allows an authenticated user to choose an arbitrary filename for download (i.e., not necessarily freeswitch.log in the intended directory).
Fusionpbx Fusionpbx
6.5
CVSSv2
CVE-2021-43404
An issue exists in FusionPBX prior to 4.5.30. The FAX file name may have risky characters.
Fusionpbx Fusionpbx
6.5
CVSSv2
CVE-2021-43405
An issue exists in FusionPBX prior to 4.5.30. The fax_extension may have risky characters (it is not constrained to be numeric).
Fusionpbx Fusionpbx
1 Github repository
6.5
CVSSv2
CVE-2021-43406
An issue exists in FusionPBX prior to 4.5.30. The fax_post_size may have risky characters (it is not constrained to preset values).
Fusionpbx Fusionpbx
9
CVSSv2
CVE-2019-16965
resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative malicious users to execute any commands on the host as www-data.
Fusionpbx Fusionpbx
4.3
CVSSv2
CVE-2019-16969
In FusionPBX up to 4.5.7, the file app\fifo_list\fifo_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.
Fusionpbx Fusionpbx
4.3
CVSSv2
CVE-2019-16972
In FusionPBX up to 4.5.7, the file app\contacts\contact_addresses.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.
Fusionpbx Fusionpbx
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
encryption
CVE-2024-4331
CVE-2024-26925
arbitrary code
CVE-2006-4304
CVE-2024-25458
CVE-2024-27077
reflected XSS
CVE-2024-4059
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »