Cross-Site Scripting Vulnerability in FusionPBX by FusionPBX
CVE-2019-19385
6.1MEDIUM
What is CVE-2019-19385?
A cross-site scripting vulnerability exists in the app/dialplans/dialplans.php file of FusionPBX version 4.4.1. This flaw allows remote attackers to inject arbitrary web scripts or HTML code via the app_uuid parameter. Exploiting this vulnerability could allow an attacker to execute malicious code in the context of the affected user's session, which can lead to unauthorized actions and data breaches.
