CVE-2019-16966: XSS
An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for FreePBX 14.0.10.3. In the Contactmanager class (html\admin\modules\contactmanager\Contactmanager.class.php), an unsanitized group variable coming from the URL is reflected in HTML on 2 occasions, leading to XSS. It can be requested via a GET request to /admin/ajax.php?module=contactmanager.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-16966?
CVE-2019-16966 is a vulnerability in Contactmanager in FreePBX versions 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 that allows for reflected XSS attacks.
How does CVE-2019-16966 affect FreePBX?
CVE-2019-16966 affects FreePBX versions 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 by allowing an attacker to execute malicious scripts in a victim's browser.
What is the severity of CVE-2019-16966?
The severity of CVE-2019-16966 is medium, with a CVSS score of 6.1.
How can I fix CVE-2019-16966?
To fix CVE-2019-16966, upgrade to FreePBX versions 13.0.45.3, 14.0.5.12, or 15.0.8.21 or apply the patch provided by FreePBX.
Where can I find more information about CVE-2019-16966?
You can find more information about CVE-2019-16966 in the references section: [reference 1](https://github.com/FreePBX/contactmanager/commit/99e5aa0050224289cfe64c9036f38ce2531bf633), [reference 2](https://issues.freepbx.org/browse/FREEPBX-20437), [reference 3](https://resp3ctblog.wordpress.com/2019/10/19/freepbx-xss-1/).