PT-2019-12292 · Fusionpbx · Fusionpbx

Dustin Cobb

·

Published

2019-06-17

·

Updated

2019-06-18

·

CVE-2019-11407

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FusionPBX version 4.4.3
Description The issue is related to excessive debug information in the Operator Panel module, specifically in the app/operator panel/index inc.php file. This allows authenticated administrative attackers to obtain credentials and other sensitive information.
Recommendations For FusionPBX version 4.4.3, consider disabling the debug information in the Operator Panel module as a temporary workaround until a patch is available. Restrict access to the Operator Panel module to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11407

Affected Products

Fusionpbx