Cross Site Scripting Vulnerability in FusionPBX by FusionPBX
CVE-2020-21053
6.1MEDIUM
What is CVE-2020-21053?
A Cross Site Scripting vulnerability exists in FusionPBX 4.5.7, which allows remote attackers to inject arbitrary web scripts or HTML into the application. This is accomplished via an unsanitized 'query_string' variable found in the device_imports.php file. Exploitation of this vulnerability can lead to unauthorized actions on behalf of users, compromising the integrity and security of the application.
