vendor:
FusionPBX
by:
Luska
8.8
CVSS
HIGH
Remote Code Execution (RCE)
20
CWE
Product Name: FusionPBX
Affected Version From: 4.5.29
Affected Version To: 4.5.30
Patch Exists: YES
Related CWE: CVE-2021-43405
CPE: a:fusionpbx:fusionpbx
Platforms Tested: Debian
2021
FusionPBX 4.5.29 – Remote Code Execution (RCE) (Authenticated)
FusionPBX is a full-featured multi-tenant GUI for FreeSWITCH. A vulnerability in FusionPBX version 4.5.29 and earlier allows an authenticated user to execute arbitrary code on the server. The vulnerability exists due to insufficient validation of user-supplied input in the 'fax_extension' parameter of the 'fax_send.php' script. An attacker can send a specially crafted HTTP request containing an arbitrary command, which will be executed on the server.
Mitigation:
Upgrade to version 4.5.30 or later.