XSS Injection Vulnerability in Sangoma FreePBX and PBXact Products
CVE-2019-19852

4.8MEDIUM

Key Information:

Vendor

Sangoma

Status
Vendor
CVE Published:
16 March 2020

What is CVE-2019-19852?

An XSS Injection vulnerability is present in the Sangoma FreePBX and PBXact systems which can be exploited through the Call Event Logging (CEL) report screen. Attackers may manipulate date fields in the admin/config.php?display=cel URI, potentially allowing for the execution of malicious scripts within the context of the user's browser session. This vulnerability affects several versions of FreePBX and PBXact, exposing the systems to risks of unauthorized actions and data leakage.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.