Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4wxw-w756-wvc6

Опубликовано: 31 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any retrieved file in place of the expected report.

This issue affects CompletePBX: all versions up to and prior to 5.2.35

Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any retrieved file in place of the expected report.

This issue affects CompletePBX: all versions up to and prior to 5.2.35

EPSS

Процентиль: 99%
0.74713
Высокий

6.7 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.3
nvd
10 месяцев назад

Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any retrieved file in place of the expected report. This issue affects CompletePBX: all versions up to and prior to 5.2.35

EPSS

Процентиль: 99%
0.74713
Высокий

6.7 Medium

CVSS3

Дефекты

CWE-22