PT-2019-9197 · Sangoma · Freepbx
Published
2019-06-20
·
Updated
2019-12-10
·
CVE-2018-15891
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FreePBX core versions prior to 3.0.122.43
FreePBX core versions prior to 14.0.18.34
FreePBX core versions prior to 5.0.1beta4
Description
An issue was discovered that allows an attacker to store JavaScript commands in a module name by crafting a request for adding Asterisk modules.
Recommendations
For versions prior to 3.0.122.43, update to version 3.0.122.43 or later.
For versions prior to 14.0.18.34, update to version 14.0.18.34 or later.
For versions prior to 5.0.1beta4, update to version 5.0.1beta4 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freepbx