Sangoma

Switchvox

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 17.07.2026 15:59:23
  • Zuletzt bearbeitet 17.07.2026 18:04:04

A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_modify_voicemail_template endpoint fails to properly sanitize HTML content sup...

  • EPSS 0.23%
  • Veröffentlicht 17.07.2026 15:58:25
  • Zuletzt bearbeitet 17.07.2026 18:04:04

An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the sound_path parameter and fails to properly validate file paths before acce...

  • EPSS 0.41%
  • Veröffentlicht 17.07.2026 15:57:42
  • Zuletzt bearbeitet 12.08.2026 20:17:57

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL qu...

  • EPSS 0.1%
  • Veröffentlicht 12.05.2026 01:16:47
  • Zuletzt bearbeitet 13.05.2026 15:46:19

Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.

Exploit
  • EPSS 0.9%
  • Veröffentlicht 14.02.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 06:32:04

Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to an improper access restriction. Users information such as first name, last name, acount id, server uuid, email address, profile im...