Command Injection Vulnerability in FusionPBX by FusionPBX
CVE-2022-35153
9.8CRITICAL
What is CVE-2022-35153?
A command injection vulnerability has been identified in FusionPBX version 5.0.1, specifically through the /fax/fax_send.php endpoint. This flaw can allow attackers to execute arbitrary commands on the server, potentially leading to unauthorized access and manipulation of the system. It is crucial for users and administrators to apply security patches and implement necessary configurations to mitigate this risk.
