FusionPBX
35 exploits
Active since Jun 2019
FusionPBX 4.5.7 - Stored Cross-Site Scripting via Device Imports Query String
CVSS 6.1
FusionPBX 4.5.7 - Path Traversal via File Rename Parameters
CVSS 6.5
FusionPBX 4.5.7 - Path Traversal via folder Variable in foldernew.php
CVSS 4.3
FusionPBX 4.5.7 - Path Traversal via app/edit/folderdelete.php
CVSS 8.1
FusionPBX <4.5.30 - Info Disclosure
CVSS 6.5
FusionPBX <4.5.30 - Info Disclosure
CVSS 8.8
FusionPBX <4.5.30 - Info Disclosure
CVSS 8.8
FusionPBX < 4.4.0 - OS Command Injection via Email Log Download
CVSS 9.8
FusionPBX 5.0.1 - OS Command Injection via Fax Send Endpoint
CVSS 9.8
FusionPBX <5.2.0 - Privilege Escalation
CVSS 5.3