CVE-2019-11408
Last modified
CVE-2019-11408 is a vulnerability of currently unknown severity. XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject arbitrary JavaScript characters by placing a phone call using a specially crafted caller ID number. This can further lead to remote code execution by chaining this vulnerability with a command injection vulnerability also present in FusionPBX.. EPSS estimates a 6.87% chance of exploitation in the next 30 days.
Description
XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject arbitrary JavaScript characters by placing a phone call using a specially crafted caller ID number. This can further lead to remote code execution by chaining this vulnerability with a command injection vulnerability also present in FusionPBX.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fusionpbx | Fusionpbx | 4.4.3 |
References
- http://packetstormsecurity.com/files/153256/FusionPBX-4.4.3-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://blog.gdssecurity.com/labs/2019/6/7/rce-using-caller-id-multiple-vulnerabilities-in-fusionpbx.htmlExploit, Third Party Advisory
- https://github.com/fusionpbx/fusionpbx/commit/391a23d070f3036d0c7760992f6970b0a76ee4d7Patch, Third Party Advisory
- http://packetstormsecurity.com/files/153256/FusionPBX-4.4.3-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://blog.gdssecurity.com/labs/2019/6/7/rce-using-caller-id-multiple-vulnerabilities-in-fusionpbx.htmlExploit, Third Party Advisory
- https://github.com/fusionpbx/fusionpbx/commit/391a23d070f3036d0c7760992f6970b0a76ee4d7Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11408?
How severe is CVE-2019-11408?
How do I fix CVE-2019-11408?
Are you affected by CVE-2019-11408?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
