Directory Traversal Vulnerability in FusionPBX by FusionPBX
CVE-2020-21057

8.1HIGH

Key Information:

Vendor

Fusionpbx

Status
Vendor
CVE Published:
20 May 2021

What is CVE-2020-21057?

The FusionPBX 4.5.7 version is susceptible to a directory traversal issue, permitting a remote attacker to exploit the 'folder' variable in app/edit/folderdelete.php. This flaw can lead to unauthorized deletion of folders on the system, potentially compromising sensitive data or disrupting service. It is essential for users of FusionPBX to implement security measures to mitigate this risk and ensure proper access controls are in place.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.