VYPR
Medium severity4.8NVD Advisory· Published Mar 16, 2020· Updated Jun 17, 2026

CVE-2019-19851

CVE-2019-19851

Description

An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Superfecta module at the admin/config.php?display=superfecta URI. This affects Superfecta through 13.0.4.7, 14.x through 14.0.24, and 15.x through 15.0.2.20.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Freepbx/Freepbx2 versions
    cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*range: <=13.0.4.7
    • (no CPE)
  • Sangoma/FreePBXdescription
  • Freepbx/PBXactllm-create

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.