Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43h8-fqwq-8xx5

Опубликовано: 31 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Xorcom CompletePBX is vulnerable to command injection in the administrator Task Scheduler functionality, allowing for attackers to execute arbitrary commands as the root user.

This issue affects CompletePBX: all versions up to and prior to 5.2.35

Xorcom CompletePBX is vulnerable to command injection in the administrator Task Scheduler functionality, allowing for attackers to execute arbitrary commands as the root user.

This issue affects CompletePBX: all versions up to and prior to 5.2.35

EPSS

Процентиль: 99%
0.78591
Высокий

9.1 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.8
nvd
10 месяцев назад

Xorcom CompletePBX is vulnerable to command injection in the administrator Task Scheduler functionality, allowing for attackers to execute arbitrary commands as the root user. This issue affects CompletePBX: all versions up to and prior to 5.2.35

EPSS

Процентиль: 99%
0.78591
Высокий

9.1 Critical

CVSS3

Дефекты

CWE-78