CVE-2019-16985

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
21/10/2019
Last modified:
03/02/2023

Description

In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 decoded and allows deletion of any file of the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fusionpbx:fusionpbx:*:*:*:*:*:*:*:* 4.5.7 (including)