Cross-Site Scripting Vulnerability in FusionPBX by FusionPBX
CVE-2019-19367
6.1MEDIUM
What is CVE-2019-19367?
A cross-site scripting vulnerability in the FusionPBX application allows remote attackers to inject arbitrary web scripts or HTML into the system via the 'id' parameter in the fax_files.php file. This flaw could lead to malicious scripts being executed in the context of the user’s browser, potentially compromising sensitive information and user sessions.
