Log Viewer File Download Exposure in FusionPBX
CVE-2021-43403

6.5MEDIUM

Key Information:

Vendor

Fusionpbx

Status
Vendor
CVE Published:
29 September 2022

What is CVE-2021-43403?

FusionPBX versions prior to 4.5.30 contain a vulnerability in the log_viewer.php Log View page, which allows an authenticated user to choose and download arbitrary file names, compromising the intended security of log file access. This flaw enables potential exposure of sensitive data, as users can access files outside the designated freeswitch.log, posing a significant risk to system integrity.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.