CVE-2019-16983

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
21/10/2019
Last modified:
03/02/2023

Description

In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface), which uses an unsanitized "param" variable constructed partially from the URL args and reflected in HTML, leading to XSS.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fusionpbx:fusionpbx:*:*:*:*:*:*:*:* 4.5.7 (including)