Vulnerability index

Browse CVEs

50 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fusionpbx HIGH 7.2
CVE-2019-16965

resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticat…

Fix: after 4.5.7
Fix from $1,950 2019-10-21
Fusionpbx MEDIUM 6.5
CVE-2019-16985

In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 decoded an…

Fix: after 4.5.7
Fix from $1,600 2019-10-21
Fusionpbx MEDIUM 6.5
CVE-2019-16986

In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname and allows …

Fix: after 4.5.7
Fix from $1,600 2019-10-21
Fusionpbx MEDIUM 6.1
CVE-2019-16987

In FusionPBX up to v4.5.7, the file app\contacts\contact_import.php uses an unsanitized "query_string" variable coming from the URL, which is reflect…

Fix: after 4.5.7
Fix from $1,600 2019-10-21
Fusionpbx MEDIUM 6.1
CVE-2019-16988

In FusionPBX up to v4.5.7, the file app\basic_operator_panel\resources\content.php uses an unsanitized "eavesdrop_dest" variable coming from the URL,…

Fix: after 4.5.7
Fix from $1,600 2019-10-21
Fusionpbx MEDIUM 6.1
CVE-2019-16989

In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable coming from the URL, which is …

Fix: after 4.5.7
Fix from $1,600 2019-10-21
Fusionpbx MEDIUM 6.1
CVE-2019-16991

In FusionPBX up to v4.5.7, the file app\edit\filedelete.php uses an unsanitized "file" variable coming from the URL, which is reflected in HTML, lead…

Fix: after 4.5.7
Fix from $1,600 2019-10-21
Fusionpbx MEDIUM 6.1
CVE-2019-16981

In FusionPBX up to v4.5.7, the file app\conference_profiles\conference_profile_params.php uses an unsanitized "id" variable coming from the URL, whic…

Fix: after 4.5.7
Fix from $1,600 2019-10-21
Fusionpbx MEDIUM 6.1
CVE-2019-16982

In FusionPBX up to v4.5.7, the file app\access_controls\access_control_nodes.php uses an unsanitized "id" variable coming from the URL, which is refl…

Fix: after 4.5.7
Fix from $1,600 2019-10-21
Fusionpbx MEDIUM 6.1
CVE-2019-16983

In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface), which uses an unsanitized …

Fix: after 4.5.7
Fix from $1,600 2019-10-21
Fusionpbx MEDIUM 6.1
CVE-2019-16984

In FusionPBX up to v4.5.7, the file app\recordings\recording_play.php uses an unsanitized "filename" variable coming from the URL, which is base64 de…

Fix: after 4.5.7
Fix from $1,600 2019-10-21
Fusionpbx HIGH 8.8
CVE-2019-16980

In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an unparamete…

Fix: after 4.5.7
Fix from $1,950 2019-10-21
Fusionpbx MEDIUM 6.5
CVE-2019-16990

In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takes any path…

Fix: after 4.5.7
Fix from $1,600 2019-10-21
Fusionpbx MEDIUM 6.1
CVE-2019-16978

In FusionPBX up to v4.5.7, the file app\devices\device_settings.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 oc…

Fix: after 4.5.7
Fix from $1,600 2019-10-21
Fusionpbx MEDIUM 6.1
CVE-2019-16979

In FusionPBX up to v4.5.7, the file app\contacts\contact_urls.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, …

Fix: after 4.5.7
Fix from $1,600 2019-10-21
Fusionpbx HIGH 8.8
CVE-2019-15029EPSS 12%

FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will in…

No fix yet
Fix from $1,950 2019-09-05
Fusionpbx HIGH 8.8
CVE-2019-11409EPSS 87%

app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input val…

Patch available
Fix from $1,950 2019-06-17
Fusionpbx HIGH 7.2
CVE-2019-11410

app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation, which …

Patch available
Fix from $1,950 2019-06-17
Fusionpbx HIGH 7.2
CVE-2019-11407

app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to excessiv…

Patch available
Fix from $1,950 2019-06-17
Fusionpbx MEDIUM 6.1
CVE-2019-11408EPSS 7%

XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject arbitrary J…

Patch available
Fix from $1,600 2019-06-17