← Back

Fusionpbx

fusionpbx

52 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Fusionpbx
fusionpbx

CVEs (52)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Nov 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to 4.5.7, the file app\extensions\extension_imports.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to 4.5.7, the file app\contacts\contact_notes.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to 4.5.7, the file app\destinations\destination_imports.php uses an unsanitized "query_string" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to 4.5.7, the file app\contacts\contact_edit.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to 4.5.7, the file app\contacts\contact_addresses.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to 4.5.7, the file app\messages\messages_thread.php uses an unsanitized "contact_uuid" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to 4.5.7, the file app\contacts\contact_times.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to 4.5.7, the file app\fifo_list\fifo_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to 4.5.7, the file app\sip_status\sip_status.php uses an unsanitized "savemsg" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in FusionPBX up to 4.5.7. In the file app\conference_controls\conference_control_details.php, an unsanitized id variable coming from the URL is reflected in HTML on 2 occasions, leading to XSS.
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 21, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute any commands on the host as www-...Show more
resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute any commands on the host as www-data.Show less
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 21, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated attackers (with at least the...Show more
app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated attackers (with at least the permission call_center_queue_add or call_center_queue_edit) to execute any commands on the host as www-data.Show less
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to v4.5.7, the file app\edit\filedelete.php uses an unsanitized "file" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to v4.5.7, the file app\basic_operator_panel\resources\content.php uses an unsanitized "eavesdrop_dest" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to v4.5.7, the file app\contacts\contact_import.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname and allows a download of it. (resources\secure_download.php is also affected.)
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 21, 2019
N/A· v4
6.5 MEDIUM· v3
8.5 HIGH· v2
In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 decoded and allows deletion of any file of the system.
1Fusionpbx
1Fusionpbx
Nov 21, 2024
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to v4.5.7, the file app\recordings\recording_play.php uses an unsanitized "filename" variable coming from the URL, which is base64 decoded and reflected in HTML, leading to XSS.