First published: Mon Jun 17 2019(Updated: )
app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute commands on the host.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fusionpbx Fusionpbx | =4.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11410 has a medium severity rating due to its potential for command injection by authenticated users.
To fix CVE-2019-11410, update FusionPBX to version 4.4.4 or later, which contains the necessary security patches.
CVE-2019-11410 affects FusionPBX version 4.4.3 installations, particularly those with administrative access.
The potential impacts of CVE-2019-11410 include unauthorized remote command execution by attackers with administrative credentials.
CVE-2019-11410 can be exploited by authenticated administrative users, making it a significant risk if proper input validation is not applied.