vendor:
FreePBX
by:
Ivan Huertas
4,3
CVSS
MEDIUM
Permanent Cross-Site Scripting (XSS)
79
CWE
Product Name: FreePBX
Affected Version From: 2.5.x
Affected Version To: 2.6.0
Patch Exists: YES
Related CWE: N/A
CPE: a:freepbx:freepbx
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Any running FreePBX 2.5.x and 2.6.0
2010
Permanent Cross-Site Scripting (XSS) in FreePBX 2.5.x – 2.6.0
A permanent Cross Site Scripting vulnerability was found in FreePBX 2.5.x and 2.6, because the application fails to sanitize user-supplied input. The vulnerability can be triggered by any logged-in user who is able to add an Inbound Route.
Mitigation:
Upgrade to the latest version