PT-2024-19862 · Fusionpbx · Fusionpbx

Satoshi Horikoshi

·

Published

2024-01-18

·

Updated

2025-05-30

·

CVE-2024-23387

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FusionPBX versions prior to 5.1.0
Description The issue allows a remote authenticated attacker with administrative privileges to execute an arbitrary script on the web browser of the user logging in to the product. This is achieved through a cross-site scripting vulnerability.
Recommendations For versions prior to 5.1.0, update to version 5.1.0 or later to resolve the issue. As a temporary workaround, consider restricting administrative access to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-23387

Affected Products

Fusionpbx