VYPR
Vendor

FusionPBX

Products
1
CVEs
52
Across products
52
Status
Private

Products

1

Recent CVEs

52
View all 52 CVEs →
  • CVE-2019-11409HigJun 17, 2019
    risk 0.67cvss 8.8epss 0.87

    app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation that allows authenticated non-administrative attackers to execute commands on the host. This can further lead to remote…

  • CVE-2021-43405HigNov 5, 2021
    risk 0.63cvss 8.8epss 0.36

    An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained to be numeric).

  • CVE-2019-15029HigSep 5, 2019
    risk 0.61cvss 8.8epss 0.12

    FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will insert the malicious command into the database). To trigger the command, one needs to call the services.php file via a GET request…

  • CVE-2021-43406HigNov 5, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in FusionPBX before 4.5.30. The fax_post_size may have risky characters (it is not constrained to preset values).

  • CVE-2021-43404HigNov 5, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in FusionPBX before 4.5.30. The FAX file name may have risky characters.

  • CVE-2019-16964HigOct 21, 2019
    risk 0.57cvss 8.8epss 0.02

    app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated attackers (with at least the permission call_center_queue_add or call_center_queue_edit)…

  • CVE-2020-21057HigMay 20, 2021
    risk 0.53cvss 8.1epss 0.02

    Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php.

  • CVE-2019-16980HigOct 21, 2019
    risk 0.50cvss 8.8epss 0.01

    In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an unparameterized SQL query, leading to SQL injection.

  • CVE-2019-11410HigJun 17, 2019
    risk 0.47cvss 7.2epss 0.03

    app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute commands on the host.

  • CVE-2019-11407HigJun 17, 2019
    risk 0.47cvss 7.2epss 0.02

    app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to excessive debug information, which allows authenticated administrative attackers to obtain credentials and other sensitive information.

  • CVE-2021-43403MedSep 29, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in FusionPBX before 4.5.30. The log_viewer.php Log View page allows an authenticated user to choose an arbitrary filename for download (i.e., not necessarily freeswitch.log in the intended directory).

  • CVE-2020-21055MedMay 20, 2021
    risk 0.42cvss 6.5epss 0.01

    A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2) filename, and (3) newfilename variables in app\edit\filerename.php.

  • CVE-2021-37524MedJul 1, 2022
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.26 allows remote unauthenticated users to inject arbitrary web script or HTML via an unsanitized "path" parameter in resources/login.php.

  • CVE-2020-21054MedMay 20, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "f" variable in app\vars\vars_textarea.php.

  • CVE-2020-21053MedMay 20, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scriptiong (XSS) vulnerability exists in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "query_string" variable in app\devices\device_imports.php.

  • CVE-2019-19388MedNov 29, 2019
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the dialplan_uuid parameter.

  • CVE-2019-19387MedNov 29, 2019
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the c parameter.

  • CVE-2019-19386MedNov 29, 2019
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id and/or voicemail_id parameter.

  • CVE-2019-19385MedNov 29, 2019
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the app_uuid parameter.

  • CVE-2019-19384MedNov 29, 2019
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the fax_uuid parameter.