3.5
CVSSv2

CVE-2019-19852

Published: 16/03/2020 Updated: 19/03/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report screen in the cel module at the admin/config.php?display=cel URI via date fields. This affects cel up to and including 13.0.26.9, 14.x up to and including 14.0.2.14, and 15.x up to and including 15.0.15.4.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sangoma freepbx