PT-2022-11698 · Freepbx · Freepbx

Kguptasangom

·

Published

2022-12-27

·

Updated

2024-05-17

·

CVE-2021-4282

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FreePBX versions prior to 14.0.6.25
Description A vulnerability was found in FreePBX voicemail, affecting an unknown functionality of the file page.voicemail.php. The manipulation leads to cross site scripting. The attack can be launched remotely.
Recommendations For versions prior to 14.0.6.25, upgrade to version 14.0.6.25 to address this issue. As a temporary workaround, consider restricting access to the page.voicemail.php file until the upgrade is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-4282

Affected Products

Freepbx