Command Injection Vulnerability in FusionPBX Call Center Queue Module
CVE-2019-16964
8.8HIGH
What is CVE-2019-16964?
The Call Center Queue Module in FusionPBX versions up to 4.5.7 contains a command injection vulnerability due to inadequate input validation. This flaw allows authenticated users, who possess permissions such as call_center_queue_add or call_center_queue_edit, to execute arbitrary commands on the server as the www-data user. An attacker could exploit this vulnerability to gain control over the affected system, potentially leading to further exploitation or data breaches.
