vendor:
ASTPP
by:
Fabien AUNAY
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: ASTPP
Affected Version From: 4.0.1
Affected Version To: 4.0.1
Patch Exists: YES
Related CWE: -
CPE: a:astppbilling:astpp:4.0.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Debian 9, CentOS 7
2019
ASTPP VoIP 4.0.1 – Remote Code Execution
ASTPP 4.0.1 VoIP Billing Chained Remote Root is vulnerable to Remote Code Execution. An attacker can inject malicious HTML code in SIP Caller Number, XSS injection in SIP Caller Name, XSS document.cookie evasion, XSS document.cookie grabber, Command Injection, Reverse Shell, Root the system and Looting.
Mitigation:
The user should update the ASTPP VoIP 4.0.1 to the latest version.