CVE-2019-11407

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
17/06/2019
Last modified:
18/06/2019

Description

app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to excessive debug information, which allows authenticated administrative attackers to obtain credentials and other sensitive information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fusionpbx:fusionpbx:4.4.3:*:*:*:*:*:*:*