First published: Mon Oct 21 2019(Updated: )
In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 decoded and allows deletion of any file of the system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fusionpbx Fusionpbx | <=4.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16985 has been assigned a medium severity rating due to the potential for arbitrary file deletion.
To fix CVE-2019-16985, upgrade to FusionPBX version 4.5.8 or later, where the vulnerability is addressed.
CVE-2019-16985 allows an attacker to delete any file on the server, leading to potential data loss and service disruption.
CVE-2019-16985 affects FusionPBX versions up to and including 4.5.7.
Yes, CVE-2019-16985 has been discussed in various blog posts detailing how the vulnerability can be exploited.