Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-30005

Опубликовано: 31 мар. 2025
Источник: nvd
CVSS3: 8.3
EPSS Высокий

Описание

Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any retrieved file in place of the expected report.

This issue affects CompletePBX: all versions up to and prior to 5.2.35

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:xorcom:completepbx:*:*:*:*:*:*:*:*
Версия до 5.2.36.1 (исключая)

EPSS

Процентиль: 99%
0.74713
Высокий

8.3 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.7
github
10 месяцев назад

Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any retrieved file in place of the expected report. This issue affects CompletePBX: all versions up to and prior to 5.2.35

EPSS

Процентиль: 99%
0.74713
Высокий

8.3 High

CVSS3

Дефекты

CWE-22