CVE-2017-15359

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
18/10/2017
Last modified:
20/04/2025

Description

In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/RecordingList/DownloadRecord?file=" and "/api/SupportInfo?file=" are the vulnerable parameters. An attacker must be authenticated to exploit this issue to access sensitive information to aid in subsequent attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:3cx:3cx:15.5.3554.1:*:*:*:*:*:*:*