PT-2022-11698 · Freepbx · Freepbx
Kguptasangom
·
Published
2022-12-27
·
Updated
2024-05-17
·
CVE-2021-4282
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FreePBX versions prior to 14.0.6.25
Description
A vulnerability was found in FreePBX voicemail, affecting an unknown functionality of the file page.voicemail.php. The manipulation leads to cross site scripting. The attack can be launched remotely.
Recommendations
For versions prior to 14.0.6.25, upgrade to version 14.0.6.25 to address this issue. As a temporary workaround, consider restricting access to the page.voicemail.php file until the upgrade is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freepbx