Log Viewer File Download Exposure in FusionPBX
CVE-2021-43403
6.5MEDIUM
What is CVE-2021-43403?
FusionPBX versions prior to 4.5.30 contain a vulnerability in the log_viewer.php Log View page, which allows an authenticated user to choose and download arbitrary file names, compromising the intended security of log file access. This flaw enables potential exposure of sensitive data, as users can access files outside the designated freeswitch.log, posing a significant risk to system integrity.
