361,800
Total CVEs
26,223
Critical
85,816
High
1,626
CISA KEV
0
This Week
52 results · Page 1/3
FusionPBX before 5.2.0 does not validate a session.
fusionpbx
FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is logging in to the product.
fusionpbx
An issue was discovered in FusionPBX before 4.5.30. The log_viewer.php Log View page allows an authenticated user to choose an arbitrary filename for download (i.e., not necessarily freeswitch.log in the intended directory).
fusionpbx
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
fusionpbx