VYPR
Vendor

VitalPBX

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2023-0480HigApr 4, 2023
    risk 0.57cvss 8.8epss 0.00

    VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance administrator's account. This is possible because the application is vulnerable to CSRF.

  • CVE-2024-24386HigFeb 15, 2024
    risk 0.47cvss 7.2epss 0.01

    An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalpbx/scripts folder.

  • CVE-2023-0486MedApr 4, 2023
    risk 0.40cvss 6.1epss 0.00

    VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance's administrator account via a malicious link. This is possible because the application is vulnerable to XSS.

  • CVE-2022-29330MedJun 24, 2022
    risk 0.32cvss 4.9epss 0.01

    Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails files via unspecified vectors.