PT-2019-9197 · Sangoma · Freepbx

Publicado

2019-06-20

·

Atualizado

2019-12-10

·

CVE-2018-15891

CVSS v3.1

4.8

Média

VetorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FreePBX core versions prior to 3.0.122.43 FreePBX core versions prior to 14.0.18.34 FreePBX core versions prior to 5.0.1beta4
Description An issue was discovered that allows an attacker to store JavaScript commands in a module name by crafting a request for adding Asterisk modules.
Recommendations For versions prior to 3.0.122.43, update to version 3.0.122.43 or later. For versions prior to 14.0.18.34, update to version 14.0.18.34 or later. For versions prior to 5.0.1beta4, update to version 5.0.1beta4 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-15891

Produtos afetados

Freepbx