PT-2009-4266 · Sangoma · Freepbx

Published

2009-05-28

·

Updated

2019-12-10

·

CVE-2009-1801

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: FreePBX versions 2.4.x through 2.5.1 FreePBX pre-release versions 2.6.x
Description: The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the display parameter to "reports.php", the order and extdisplay parameters to "config.php", and the sort parameter to "recordings/index.php".
Recommendations: For FreePBX versions 2.4.x through 2.5.1, consider restricting access to the affected parameters display, order, extdisplay, and sort in their respective files until a patch is available. For FreePBX pre-release versions 2.6.x, restrict access to the same parameters to minimize the risk of exploitation. As a temporary workaround, consider disabling the affected API endpoints "reports.php", "config.php", and "recordings/index.php" until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1801

Affected Products

Freepbx