CVE-2018-15891: XSS
Published Jun 20, 2019
·Updated
An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4. By crafting a request for adding Asterisk modules, an attacker is able to store JavaScript commands in a module name.
Affected Software
5 affected components
FreePBX FreePBX=15.0.1
Sangoma FreePBX <13.0.122.43
Sangoma FreePBX >=14.0.0<14.0.18.34
Sangoma FreePBX >=15.0.0<=15.0.1
Sangoma FreePBX =15.0.1-beta4
Event History
Jun 20, 2019
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-15891?
The severity of CVE-2018-15891 is medium, with a severity value of 4.8.
2
How does CVE-2018-15891 affect FreePBX?
CVE-2018-15891 affects FreePBX versions 3.0.122.43, 14.0.18.34, and 5.0.1beta4.
3
How can an attacker exploit CVE-2018-15891?
An attacker can exploit CVE-2018-15891 by crafting a request for adding Asterisk modules and storing JavaScript commands in a module name.
4
Is there a fix for CVE-2018-15891?
Yes, there is a fix for CVE-2018-15891. It is recommended to upgrade FreePBX to version 3.0.122.43, 14.0.18.34, or 5.0.1beta4.
5
Where can I find more information about CVE-2018-15891?
You can find more information about CVE-2018-15891 on the FreePBX Wiki and FreePBX website.