Command Injection Vulnerability in FusionPBX by FusionPBX
CVE-2022-28055
9.8CRITICAL
What is CVE-2022-28055?
FusionPBX versions up to 4.4 are susceptible to a command injection vulnerability through the email logs download function. This flaw allows an attacker to execute arbitrary commands on the system, posing a significant security risk. Mitigation is urgently recommended to protect the integrity of the affected systems.
