FusionPBX
35 exploits
Active since Jun 2019
FusionPBX 4.4.3 - Unauthenticated Stored Cross-Site Scripting via Caller ID
CVSS 6.1
FusionPBX 4.4.3 - Command Injection
CVSS 8.8
FusionPBX <4.5.30 - Info Disclosure
CVSS 8.8
FusionPBX 5.0.1 - OS Command Injection via Fax Send Endpoint
CVSS 9.8
FusionPBX <5.2.0 - Privilege Escalation
CVSS 5.3
FusionPBX 4.4.3 - Authenticated Sensitive Information Exposure via Operator Panel Debug Information
CVSS 7.2
FusionPBX < 4.5.7 - Cross-Site Scripting via conference_control_details.php id Parameter
CVSS 6.1
FusionPBX < 4.5.7 - Cross-Site Scripting via sip_status.php savemsg Parameter
CVSS 6.1
FusionPBX < 4.5.7 - Cross-Site Scripting via Unsanitized contact_uuid Variable
CVSS 6.1
FusionPBX < 4.5.7 - Cross-Site Scripting via Unsanitized ID Parameter
CVSS 6.1
FusionPBX < 4.5.7 - Cross-Site Scripting via Unsanitized Query String
CVSS 6.1
FusionPBX < 4.5.7 - Cross-Site Scripting via Unsanitized ID Parameter
CVSS 6.1
FusionPBX < 4.5.7 - Cross-Site Scripting via Unsanitized ID Parameter
CVSS 6.1
FusionPBX < 4.5.7 - Cross-Site Scripting via Unsanitized Query String
CVSS 6.1
FusionPBX < 4.5.7 - Cross-Site Scripting via Unsanitized Query String
CVSS 6.1
FusionPBX < 4.5.7 - Cross-Site Scripting via Unsanitized ID Parameter
CVSS 6.1
FusionPBX < 4.5.7 - Cross-Site Scripting via Unsanitized ID Parameter
CVSS 6.1
FusionPBX < 4.5.7 - Cross-Site Scripting via Paging Function
CVSS 6.1
FusionPBX < 4.5.7 - Unauthenticated Path Traversal and Arbitrary File Deletion via xml_cdr_delete.php
CVSS 6.5
FusionPBX < 4.5.7 - Cross-Site Scripting via Unsanitized Query String
CVSS 6.1
FusionPBX < 4.5.7 - Cross-Site Scripting via Eavesdrop Destination Parameter
CVSS 6.1
FusionPBX < 4.5.7 - Cross-Site Scripting via Unsanitized File Parameter
CVSS 6.1
FusionPBX 4.4.1 - Stored Cross-Site Scripting via Fax Files ID Parameter
CVSS 6.1
FusionPBX 4.4.1 - Cross-Site Scripting via app_uuid Parameter
CVSS 6.1
FusionPBX 4.4.1 - Cross-Site Scripting via c Parameter
CVSS 6.1