CVE-2019-13176: XEE
An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST data. There is potential to use this for SSRF (reading local files, outbound HTTP, and outbound DNS).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-13176?
CVE-2019-13176 is a vulnerability in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2 that allows XXE via a crafted XML document in POST data, which can be used for SSRF.
What is the severity of CVE-2019-13176?
The severity of CVE-2019-13176 is high with a CVSS score of 7.5.
What is the affected software version?
The affected software versions are 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2.
How can CVE-2019-13176 be exploited?
CVE-2019-13176 can be exploited by sending crafted XML documents in POST data to the affected software.
Is there a fix for CVE-2019-13176?
Yes, updating to a version of the 3CX Phone system (web) management console that is not affected by the vulnerability will fix CVE-2019-13176.