CVE-2018-15891
20.06.2019, 17:15
An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4. By crafting a request for adding Asterisk modules, an attacker is able to store JavaScript commands in a module name.
Vendor | Product | Version |
---|---|---|
freepbx | freepbx | 15.0.1 |
sangoma | freepbx | 𝑥 < 13.0.122.43 |
sangoma | freepbx | 14.0.0 ≤ 𝑥 < 14.0.18.34 |
sangoma | freepbx | 15.0.0 ≤ 𝑥 ≤ 15.0.1 |
sangoma | freepbx | 15.0.1:beta4 |
𝑥
= Vulnerable software versions