Command Injection Vulnerability in FusionPBX Backup Module
CVE-2019-11410
7.2HIGH
What is CVE-2019-11410?
A command injection vulnerability exists in the Backup Module of FusionPBX version 4.4.3, specifically in the app/backup/index.php file. This flaw is due to inadequate input validation, allowing authenticated administrative users to execute arbitrary commands on the host system. This could potentially lead to unauthorized access and manipulation of the server hosting FusionPBX, emphasizing the need for immediate remediation and security best practices.
