Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
fusionpbx fusionpbx vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2021-43403
An issue exists in FusionPBX prior to 4.5.30. The log_viewer.php Log View page allows an authenticated user to choose an arbitrary filename for download (i.e., not necessarily freeswitch.log in the intended directory).
Fusionpbx Fusionpbx
8.8
CVSSv3
CVE-2021-43404
An issue exists in FusionPBX prior to 4.5.30. The FAX file name may have risky characters.
Fusionpbx Fusionpbx
8.8
CVSSv3
CVE-2021-43405
An issue exists in FusionPBX prior to 4.5.30. The fax_extension may have risky characters (it is not constrained to be numeric).
Fusionpbx Fusionpbx
1 Github repository
8.8
CVSSv3
CVE-2021-43406
An issue exists in FusionPBX prior to 4.5.30. The fax_post_size may have risky characters (it is not constrained to preset values).
Fusionpbx Fusionpbx
4.8
CVSSv3
CVE-2024-23387
FusionPBX before 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is logging in to the product.
Fusionpbx Fusionpbx
9.8
CVSSv3
CVE-2022-28055
Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.
Fusionpbx Fusionpbx
8.8
CVSSv3
CVE-2019-16964
app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated attackers (with at least the permission call_center_queue_add or call_center_queue_edit) ...
Fusionpbx Fusionpbx
7.2
CVSSv3
CVE-2019-16965
resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative malicious users to execute any commands on the host as www-data.
Fusionpbx Fusionpbx
6.1
CVSSv3
CVE-2019-16968
An issue exists in FusionPBX up to 4.5.7. In the file app\conference_controls\conference_control_details.php, an unsanitized id variable coming from the URL is reflected in HTML on 2 occasions, leading to XSS.
Fusionpbx Fusionpbx
6.1
CVSSv3
CVE-2019-16969
In FusionPBX up to 4.5.7, the file app\fifo_list\fifo_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.
Fusionpbx Fusionpbx
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4946
CVE-2024-30309
CVE-2024-4761
CVE-2024-30051
type confusion
memory leak
CVE-2024-30293
reflected XSS
CVE-2024-3126
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »