Cross-Site Scripting Vulnerability in FusionPBX by FusionPBX
CVE-2019-19386
6.1MEDIUM
What is CVE-2019-19386?
A cross-site scripting vulnerability exists in the voicemail_greeting_edit.php file of FusionPBX version 4.4.1. This flaw allows remote attackers to inject arbitrary web scripts or HTML through the 'id' and/or 'voicemail_id' parameters. Exploiting this vulnerability could lead to unauthorized access or manipulation of web content, posing serious risks to the integrity and confidentiality of user interactions within the application.
