First published: Thu Aug 08 2019(Updated: )
An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST data. There is potential to use this for SSRF (reading local files, outbound HTTP, and outbound DNS).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
3CX 3CX | =12.5-sp1 | |
3CX 3CX | =12.5-sp2 | |
3CX 3CX | =12.5.44178.1002 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13176 is a vulnerability in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2 that allows XXE via a crafted XML document in POST data, which can be used for SSRF.
The severity of CVE-2019-13176 is high with a CVSS score of 7.5.
The affected software versions are 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2.
CVE-2019-13176 can be exploited by sending crafted XML documents in POST data to the affected software.
Yes, updating to a version of the 3CX Phone system (web) management console that is not affected by the vulnerability will fix CVE-2019-13176.