Medium severity6.1NVD Advisory· Published Oct 21, 2019· Updated Jun 17, 2026
CVE-2019-16967
CVE-2019-16967
Description
An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager module form (html\admin\modules\manager\views\form.php), an unsanitized managerdisplay variable coming from the URL is reflected in HTML, leading to XSS. It can be requested via GET request to /config.php?type=tool&display=manager.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- FreePBX/Managerdescription
Patches
Vulnerability mechanics
References
3- github.com/FreePBX/manager/commit/071a50983ca6a373bb2d1d3db68e9eda4667a372nvdPatchThird Party Advisory
- resp3ctblog.wordpress.com/2019/10/19/freepbx-xss-2/nvdPatchThird Party Advisory
- issues.freepbx.org/browse/FREEPBX-20436nvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.