PT-2019-12293 · Fusionpbx · Fusionpbx
Dustin Cobb
·
Published
2019-06-17
·
Updated
2019-06-18
·
CVE-2019-11408
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FusionPBX version 4.4.3
Description
The issue allows remote unauthenticated attackers to inject arbitrary JavaScript characters by placing a phone call using a specially crafted caller ID number, potentially leading to remote code execution when combined with a command injection vulnerability.
Recommendations
For FusionPBX version 4.4.3, as a temporary workaround, consider restricting access to the Operator Panel module until a patch is available. Avoid using specially crafted caller ID numbers in the
caller ID number variable to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fusionpbx