7.5
CVSSv3

CVE-2019-13176

Published: 08/08/2019 Updated: 28/08/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in the 3CX Phone system (web) management console 12.5.44178.1002 up to and including 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST data. There is potential to use this for SSRF (reading local files, outbound HTTP, and outbound DNS).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

3cx 3cx 12.5

3cx 3cx 12.5.44178.1002