PT-2019-15873 · Sangoma · Freepbx
Published
2019-12-06
·
Updated
2019-12-11
·
CVE-2019-19551
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sangoma FreePBX userman versions 13.0.76.43 through 15.0.20
Description
A security issue exists in the User Management screen of the Administrator web site, where an attacker with access to the User Control Panel application can submit malicious values in time/date formatting and time-zone fields. These fields are not properly sanitized, allowing for malicious code execution when a user, such as an admin, views the affected user's profile.
Recommendations
For Sangoma FreePBX userman versions 13.0.76.43 through 15.0.20, consider restricting access to the User Management screen until a proper fix is applied, and ensure that all input fields, especially time/date formatting and time-zone fields, are properly sanitized to prevent malicious code execution.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freepbx