CVE-2020-21055
- EPSS 1.41%
- Veröffentlicht 20.05.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:24
A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2) filename, and (3) newfilename variables in app\edit\filerename.php.
CVE-2020-21056
- EPSS 1.04%
- Veröffentlicht 20.05.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:24
Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via the folder variale to app\edit\foldernew.php.
CVE-2020-21057
- EPSS 1.26%
- Veröffentlicht 20.05.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:24
Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php.
CVE-2020-21053
- EPSS 0.33%
- Veröffentlicht 20.05.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:24
Cross Site Scriptiong (XSS) vulnerability exists in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "query_string" variable in app\devices\device_imports.php.
CVE-2019-19388
- EPSS 0.43%
- Veröffentlicht 29.11.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:41
A cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the dialplan_uuid parameter.
CVE-2019-19387
- EPSS 0.43%
- Veröffentlicht 29.11.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:41
A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the c parameter.
CVE-2019-19386
- EPSS 0.43%
- Veröffentlicht 29.11.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:41
A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id and/or voicemail_id parameter.
CVE-2019-19385
- EPSS 0.43%
- Veröffentlicht 29.11.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:41
A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the app_uuid parameter.
CVE-2019-19384
- EPSS 0.43%
- Veröffentlicht 29.11.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:41
A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the fax_uuid parameter.
CVE-2019-19367
- EPSS 0.43%
- Veröffentlicht 27.11.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:39
A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.