PT-2025-13801 · Xorcom · Xorcom Completepbx

Valentin Lobstein

·

Published

2025-03-31

·

Updated

2025-12-27

·

CVE-2025-2292

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xorcom CompletePBX versions through 5.2.35
Description The issue is an authenticated path traversal, allowing for arbitrary file reads via the Backup and Restore functionality.
Recommendations For versions through 5.2.35, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the Backup and Restore functionality until a patch is available.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-2292

Affected Products

Xorcom Completepbx