CVE-2019-16979 Information

Description

In FusionPBX up to v4.5.7 the file app\contacts\contact_urls.php uses an unsanitized \id\ variable coming from the URL which is reflected in HTML leading to XSS.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://github.com/fusionpbx/fusionpbx/commit/a76d9637e31a70060ecc38786246a8b1c9178322 https://resp3ctblog.wordpress.com/2019/10/19/fusionpbx-xss-12/ In FusionPBX up to v4.5.7 the file app\contacts\contact_urls.php uses an unsanitized \id
variable coming from the URL which is reflected in HTML leading to XSS.

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: