Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2019-19386

Disclosure Date: November 29, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id and/or voicemail_id parameter.
Attacker Value
Unknown

CVE-2019-19385

Disclosure Date: November 29, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the app_uuid parameter.
Attacker Value
Unknown

CVE-2019-19384

Disclosure Date: November 29, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the fax_uuid parameter.
Attacker Value
Unknown

CVE-2019-19388

Disclosure Date: November 29, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the dialplan_uuid parameter.
Attacker Value
Unknown

CVE-2019-19387

Disclosure Date: November 29, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the c parameter.
Attacker Value
Unknown

CVE-2019-19367

Disclosure Date: November 27, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Attacker Value
Unknown

CVE-2019-19366

Disclosure Date: November 27, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.