VYPR

FusionPBX

by FusionPBX

Source repositories

CVEs (52)

  • CVE-2019-16987MedOct 21, 2019
    risk 0.33cvss 6.1epss 0.01

    In FusionPBX up to v4.5.7, the file app\contacts\contact_import.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.

  • CVE-2019-16984MedOct 21, 2019
    risk 0.33cvss 6.1epss 0.01

    In FusionPBX up to v4.5.7, the file app\recordings\recording_play.php uses an unsanitized "filename" variable coming from the URL, which is base64 decoded and reflected in HTML, leading to XSS.

  • CVE-2019-16983MedOct 21, 2019
    risk 0.33cvss 6.1epss 0.01

    In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface), which uses an unsanitized "param" variable constructed partially from the URL args and reflected in HTML, leading to XSS.

  • CVE-2019-16982MedOct 21, 2019
    risk 0.33cvss 6.1epss 0.01

    In FusionPBX up to v4.5.7, the file app\access_controls\access_control_nodes.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

  • CVE-2019-16981MedOct 21, 2019
    risk 0.33cvss 6.1epss 0.01

    In FusionPBX up to v4.5.7, the file app\conference_profiles\conference_profile_params.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.

  • CVE-2019-16979MedOct 21, 2019
    risk 0.33cvss 6.1epss 0.01

    In FusionPBX up to v4.5.7, the file app\contacts\contact_urls.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

  • CVE-2019-16978MedOct 21, 2019
    risk 0.33cvss 6.1epss 0.01

    In FusionPBX up to v4.5.7, the file app\devices\device_settings.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.

  • CVE-2024-23387MedJan 19, 2024
    risk 0.31cvss 4.8epss 0.00

    FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is logging in to the product.

  • CVE-2020-21056MedMay 20, 2021
    risk 0.28cvss 4.3epss 0.01

    Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via the folder variale to app\edit\foldernew.php.

  • CVE-2024-24539MedMar 18, 2024
    risk 0.00cvss 5.3epss 0.01

    FusionPBX before 5.2.0 does not validate a session.

  • CVE-2022-35153CriAug 18, 2022
    risk 0.00cvss 9.8epss 0.02

    FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.

  • CVE-2022-28055CriMay 4, 2022
    risk 0.00cvss 9.8epss 0.02

    Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.

Page 3 of 3