vendor:
3CX Phone System
by:
Jens Regel, Schneider & Wulf EDV-Beratung GmbH & Co. KG
6,5
CVSS
MEDIUM
Authenticated Directory Traversal
22
CWE
Product Name: 3CX Phone System
Affected Version From: 3CX Phone System 15.5.3554.1 (Debian based installation)
Affected Version To: 3CX Phone System 15.5.3554.1 (Debian based installation)
Patch Exists: YES
Related CWE: CVE-2017-15359
CPE: a:3cx:3cx_phone_system
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
3CX Phone System – Authenticated Directory Traversal
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: '/api/RecordingList/DownloadRecord?file=' and '/api/SupportInfo?file=' are the vulnerable parameters. An attacker must be authenticated to exploit this issue to access sensitive information to aid in subsequent attacks.
Mitigation:
The vendor has confirmed the vulnerability and will be fixed in the next release.