VYPR

Vendor CVEs

FusionPBX

All CVEs

40 total · sorted by risk
  • CVE-2019-11409Jun 17, 2019
    risk 0.10cvss epss 0.86

    app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation that allows authenticated non-administrative attackers to execute commands on the host. This can further lead to remote…

  • CVE-2019-15029Sep 5, 2019
    risk 0.05cvss epss 0.21

    FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will insert the malicious command into the database). To trigger the command, one needs to call the services.php file via a GET request…

  • CVE-2019-11410Jun 17, 2019
    risk 0.01cvss epss 0.08

    app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute commands on the host.

  • CVE-2024-24539Mar 18, 2024
    risk 0.00cvss epss 0.00

    FusionPBX before 5.2.0 does not validate a session.

  • CVE-2024-23387Jan 19, 2024
    risk 0.00cvss epss 0.00

    FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is logging in to the product.

  • CVE-2019-19384Nov 28, 2019
    risk 0.00cvss epss 0.00

    A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the fax_uuid parameter.

  • CVE-2019-19385Nov 28, 2019
    risk 0.00cvss epss 0.00

    A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the app_uuid parameter.

  • CVE-2019-19386Nov 28, 2019
    risk 0.00cvss epss 0.00

    A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id and/or voicemail_id parameter.

  • CVE-2019-19387Nov 28, 2019
    risk 0.00cvss epss 0.00

    A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the c parameter.

  • CVE-2019-19388Nov 28, 2019
    risk 0.00cvss epss 0.00

    A cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the dialplan_uuid parameter.

  • CVE-2019-19366Nov 27, 2019
    risk 0.00cvss epss 0.00

    A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.

  • CVE-2019-19367Nov 27, 2019
    risk 0.00cvss epss 0.00

    A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

  • CVE-2019-16977Oct 23, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to 4.5.7, the file app\extensions\extension_imports.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.

  • CVE-2019-16975Oct 23, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to 4.5.7, the file app\contacts\contact_notes.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

  • CVE-2019-16976Oct 23, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to 4.5.7, the file app\destinations\destination_imports.php uses an unsanitized "query_string" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.

  • CVE-2019-16973Oct 22, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to 4.5.7, the file app\contacts\contact_edit.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.

  • CVE-2019-16972Oct 22, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to 4.5.7, the file app\contacts\contact_addresses.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

  • CVE-2019-16971Oct 22, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to 4.5.7, the file app\messages\messages_thread.php uses an unsanitized "contact_uuid" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.

  • CVE-2019-16974Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to 4.5.7, the file app\contacts\contact_times.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

  • CVE-2019-16969Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to 4.5.7, the file app\fifo_list\fifo_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.

  • CVE-2019-16970Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to 4.5.7, the file app\sip_status\sip_status.php uses an unsanitized "savemsg" variable coming from the URL, which is reflected in HTML, leading to XSS.

  • CVE-2019-16968Oct 21, 2019
    risk 0.00cvss epss 0.00

    An issue was discovered in FusionPBX up to 4.5.7. In the file app\conference_controls\conference_control_details.php, an unsanitized id variable coming from the URL is reflected in HTML on 2 occasions, leading to XSS.

  • CVE-2019-16965Oct 21, 2019
    risk 0.00cvss epss 0.03

    resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute any commands on the host as www-data.

  • CVE-2019-16964Oct 21, 2019
    risk 0.00cvss epss 0.03

    app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated attackers (with at least the permission call_center_queue_add or call_center_queue_edit)…

  • CVE-2019-16988Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to v4.5.7, the file app\basic_operator_panel\resources\content.php uses an unsanitized "eavesdrop_dest" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.

  • CVE-2019-16991Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to v4.5.7, the file app\edit\filedelete.php uses an unsanitized "file" variable coming from the URL, which is reflected in HTML, leading to XSS.

  • CVE-2019-16989Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.

  • CVE-2019-16986Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname and allows a download of it. (resources\secure_download.php is also affected.)

  • CVE-2019-16987Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to v4.5.7, the file app\contacts\contact_import.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.

  • CVE-2019-16985Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 decoded and allows deletion of any file of the system.

  • CVE-2019-16984Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to v4.5.7, the file app\recordings\recording_play.php uses an unsanitized "filename" variable coming from the URL, which is base64 decoded and reflected in HTML, leading to XSS.

  • CVE-2019-16983Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface), which uses an unsanitized "param" variable constructed partially from the URL args and reflected in HTML, leading to XSS.

  • CVE-2019-16981Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to v4.5.7, the file app\conference_profiles\conference_profile_params.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.

  • CVE-2019-16982Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to v4.5.7, the file app\access_controls\access_control_nodes.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

  • CVE-2019-16990Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takes any pathname (base64 encoded) and allows a download of it.

  • CVE-2019-16979Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to v4.5.7, the file app\contacts\contact_urls.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

  • CVE-2019-16980Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an unparameterized SQL query, leading to SQL injection.

  • CVE-2019-16978Oct 21, 2019
    risk 0.00cvss epss 0.00

    In FusionPBX up to v4.5.7, the file app\devices\device_settings.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.

  • CVE-2019-11408Jun 17, 2019
    risk 0.00cvss epss 0.02

    XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject arbitrary JavaScript characters by placing a phone call using a specially crafted caller ID number. This can further lead to remote code…

  • CVE-2019-11407Jun 17, 2019
    risk 0.00cvss epss 0.01

    app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to excessive debug information, which allows authenticated administrative attackers to obtain credentials and other sensitive information.