First published: Mon Oct 21 2019(Updated: )
resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute any commands on the host as www-data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fusionpbx Fusionpbx | <=4.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-16965.
The severity of CVE-2019-16965 is critical with a score of 7.2.
The affected software is FusionPBX up to version 4.5.7.
CVE-2019-16965 allows authenticated administrative attackers to execute any commands on the host as www-data.
To fix CVE-2019-16965, update FusionPBX to version 4.5.8 or later, and ensure that input validation is implemented.