Cross-Site Scripting Vulnerability in FusionPBX by FusionPBX
CVE-2019-19388

6.1MEDIUM

Key Information:

Vendor

Fusionpbx

Status
Vendor
CVE Published:
29 November 2019

What is CVE-2019-19388?

A cross-site scripting (XSS) vulnerability exists in the file app/dialplans/dialplan_detail_edit.php of FusionPBX 4.4.1. This flaw allows remote attackers to exploit the system by injecting arbitrary web scripts or HTML through the dialplan_uuid parameter, posing a significant risk to the application's security and integrity. If successfully executed, it could lead to unauthorized actions being performed on behalf of the victim user.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.