CVE-2024-24539
- EPSS 0.05%
- Veröffentlicht 18.03.2024 03:15:06
- Zuletzt bearbeitet 23.05.2025 14:43:02
FusionPBX before 5.2.0 does not validate a session.
CVE-2024-23387
- EPSS 0.1%
- Veröffentlicht 19.01.2024 04:15:09
- Zuletzt bearbeitet 30.05.2025 15:15:36
FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is ...
CVE-2021-43403
- EPSS 0.35%
- Veröffentlicht 29.09.2022 03:15:14
- Zuletzt bearbeitet 21.11.2024 06:29:10
An issue was discovered in FusionPBX before 4.5.30. The log_viewer.php Log View page allows an authenticated user to choose an arbitrary filename for download (i.e., not necessarily freeswitch.log in the intended directory).
CVE-2022-35153
- EPSS 4.42%
- Veröffentlicht 18.08.2022 05:15:07
- Zuletzt bearbeitet 21.11.2024 07:10:49
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
CVE-2021-37524
- EPSS 0.95%
- Veröffentlicht 01.07.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:15:18
Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.26 allows remote unauthenticated users to inject arbitrary web script or HTML via an unsanitized "path" parameter in resources/login.php.
CVE-2022-28055
- EPSS 5.33%
- Veröffentlicht 04.05.2022 03:15:07
- Zuletzt bearbeitet 21.11.2024 06:56:41
Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.
CVE-2021-43406
- EPSS 0.42%
- Veröffentlicht 05.11.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:29:10
An issue was discovered in FusionPBX before 4.5.30. The fax_post_size may have risky characters (it is not constrained to preset values).
CVE-2021-43405
- EPSS 5.24%
- Veröffentlicht 05.11.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:29:10
An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained to be numeric).
CVE-2021-43404
- EPSS 0.42%
- Veröffentlicht 05.11.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:29:10
An issue was discovered in FusionPBX before 4.5.30. The FAX file name may have risky characters.
CVE-2020-21054
- EPSS 0.33%
- Veröffentlicht 20.05.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:24
Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "f" variable in app\vars\vars_textarea.php.