CVE-2019-16985

MEDIUM

Fusionpbx < 4.5.7 - Path Traversal

Title source: rule
STIX 2.1

Description

In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 decoded and allows deletion of any file of the system.

Scores

CVSS v3 6.5
EPSS 0.0039
EPSS Percentile 60.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-22
Status published
Products (1)
fusionpbx/fusionpbx < 4.5.7
Published Oct 21, 2019
Tracked Since Feb 18, 2026