Описание
FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is logging in to the product.
Ссылки
- Product
- Third Party Advisory
- Product
- Product
- Third Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 5.1.0 (исключая)
cpe:2.3:a:fusionpbx:fusionpbx:*:*:*:*:*:*:*:*
EPSS
Процентиль: 28%
0.00101
Низкий
4.8 Medium
CVSS3
Дефекты
CWE-79
CWE-79
Связанные уязвимости
CVSS3: 4.8
github
около 2 лет назад
FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is logging in to the product.
EPSS
Процентиль: 28%
0.00101
Низкий
4.8 Medium
CVSS3
Дефекты
CWE-79
CWE-79