Show filters
51 Total Results
Displaying 1-10 of 51
Sort by:
Attacker Value
Unknown
CVE-2024-23387
Disclosure Date: January 19, 2024 (last updated January 25, 2024)
FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is logging in to the product.
0
Attacker Value
Unknown
CVE-2021-43403
Disclosure Date: September 29, 2022 (last updated October 08, 2023)
An issue was discovered in FusionPBX before 4.5.30. The log_viewer.php Log View page allows an authenticated user to choose an arbitrary filename for download (i.e., not necessarily freeswitch.log in the intended directory).
0
Attacker Value
Unknown
CVE-2022-35153
Disclosure Date: August 18, 2022 (last updated October 08, 2023)
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
0
Attacker Value
Unknown
CVE-2021-37524
Disclosure Date: July 01, 2022 (last updated October 07, 2023)
Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.26 allows remote unauthenticated users to inject arbitrary web script or HTML via an unsanitized "path" parameter in resources/login.php.
0
Attacker Value
Unknown
CVE-2022-28055
Disclosure Date: May 04, 2022 (last updated October 07, 2023)
Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.
0
Attacker Value
Unknown
CVE-2021-43405
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained to be numeric).
0
Attacker Value
Unknown
CVE-2021-43406
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
An issue was discovered in FusionPBX before 4.5.30. The fax_post_size may have risky characters (it is not constrained to preset values).
0
Attacker Value
Unknown
CVE-2021-43404
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
An issue was discovered in FusionPBX before 4.5.30. The FAX file name may have risky characters.
0
Attacker Value
Unknown
CVE-2020-21055
Disclosure Date: May 20, 2021 (last updated February 22, 2025)
A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2) filename, and (3) newfilename variables in app\edit\filerename.php.
0
Attacker Value
Unknown
CVE-2020-21054
Disclosure Date: May 20, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "f" variable in app\vars\vars_textarea.php.
0