PT-2018-5682 · Fonality · Trixbox
Sachin Wagh
+1
·
Published
2018-02-16
·
Updated
2022-02-19
·
CVE-2017-14537
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
trixbox version 2.8.0.4
Description:
The issue concerns path traversal via the
xajaxargs array parameter to "/maint/index.php?packages" or the lang parameter to "/maint/modules/home/index.php".Recommendations:
For trixbox version 2.8.0.4, consider restricting access to the
/maint/index.php?packages and /maint/modules/home/index.php API endpoints until a patch is available. As a temporary workaround, avoid using the xajaxargs array parameter and the lang parameter in the affected API endpoints.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trixbox