PT-2019-15873 · Sangoma · Freepbx

Published

2019-12-06

·

Updated

2019-12-11

·

CVE-2019-19551

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sangoma FreePBX userman versions 13.0.76.43 through 15.0.20
Description A security issue exists in the User Management screen of the Administrator web site, where an attacker with access to the User Control Panel application can submit malicious values in time/date formatting and time-zone fields. These fields are not properly sanitized, allowing for malicious code execution when a user, such as an admin, views the affected user's profile.
Recommendations For Sangoma FreePBX userman versions 13.0.76.43 through 15.0.20, consider restricting access to the User Management screen until a proper fix is applied, and ensure that all input fields, especially time/date formatting and time-zone fields, are properly sanitized to prevent malicious code execution.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19551

Affected Products

Freepbx