PT-2021-10579 · Fusionpbx · Fusionpbx

Pierre Jourdan

·

Published

2021-05-20

·

Updated

2021-05-25

·

CVE-2020-21056

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: FusionPBX version 4.5.7
Description: A Directory Traversal issue exists, allowing a remote malicious user to create folders via the folder variable to "appeditfoldernew.php".
Recommendations: For FusionPBX version 4.5.7, consider restricting access to the "appeditfoldernew.php" endpoint until a patch is available. As a temporary workaround, avoid using the folder variable in the affected endpoint to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-21056

Affected Products

Fusionpbx