PT-2021-8989 · Unknown · Liberty Lispbx
Fernando Pompeo Amatte
·
Published
2021-04-12
·
Updated
2021-04-21
·
CVE-2019-15059
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Liberty lisPBX versions 2.0 through 2.0-4
Description
The issue allows remote retrieval of configuration backup files without requiring authentication or authorization. These files contain sensitive PBX information, including extension numbers, contacts, and passwords, which can be accessed through specific paths, such as
/backup/lispbx-CONF-YYYY-MM-DD.tar or /backup/lispbx-CDR-YYYY-MM-DD.tar.Recommendations
For Liberty lisPBX versions 2.0 through 2.0-4, restrict access to the
/backup directory to prevent unauthorized retrieval of configuration backup files. Consider implementing proper authentication and authorization mechanisms for accessing these files.Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Liberty Lispbx