PT-2021-10580 · Fusionpbx · Fusionpbx

Pierre Jourdan

·

Published

2021-05-20

·

Updated

2021-05-25

·

CVE-2020-21057

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: FusionPBX version 4.5.7
Description: A Directory Traversal issue allows a remote malicious user to delete folders on the system. This is achieved by exploiting the folder variable in the "/app/edit/folderdelete.php" endpoint.
Recommendations: For FusionPBX version 4.5.7, consider restricting access to the "/app/edit/folderdelete.php" endpoint until a patch is available. As a temporary workaround, avoid using the folder variable in this endpoint to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-21057

Affected Products

Fusionpbx