PT-2019-15874 · Sangoma · Freepbx
Publicado
2019-12-06
·
Atualizado
2019-12-10
·
CVE-2019-19552
CVSS v3.1
4.8
Média
| Vetor | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sangoma FreePBX userman versions 13.0.76.43 through 15.0.20
Description
The issue exists in the user management screen of the Administrator website, specifically at the
/admin/config.php?display=userman API endpoint. An attacker with sufficient privileges can embed malicious code in the Display Name of a user. When another user, such as an admin, visits the main User Management screen, the malicious code will render and execute in the context of the victim user's account.Recommendations
For Sangoma FreePBX userman versions 13.0.76.43 through 15.0.20, consider restricting access to the user management screen until a fix is available. As a temporary workaround, avoid editing the
Display Name of users to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Freepbx