CVE-2019-11407

HIGH

FusionPBX 4.4.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to excessive debug information, which allows authenticated administrative attackers to obtain credentials and other sensitive information.

Scores

CVSS v3 7.2
EPSS 0.0073
EPSS Percentile 72.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-200
Status published
Products (1)
fusionpbx/fusionpbx 4.4.3
Published Jun 17, 2019
Tracked Since Feb 18, 2026