First published: Mon Mar 16 2020(Updated: )
An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Superfecta module at the admin/config.php?display=superfecta URI. This affects Superfecta through 13.0.4.7, 14.x through 14.0.24, and 15.x through 15.0.2.20.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sangoma FreePBX | <=13.0.4.7 | |
Sangoma FreePBX | >=14.0.0.0<=14.0.24 | |
Sangoma FreePBX | >=15.0.0.0<=15.0.2.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19851 is an XSS Injection vulnerability that exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Superfecta module.
Sangoma FreePBX versions 13.0.4.7, 14.x (up to 14.0.24), and 15.x (up to 15.0.2.20) are affected.
CVE-2019-19851 has a severity rating of 4.8, which is considered medium.
To fix CVE-2019-19851, it is recommended to update to the latest version of Sangoma FreePBX and PBXact.
More information about CVE-2019-19851 can be found in the references provided: [link 1](https://wiki.freepbx.org/display/FOP/2020-01-09+XSS+Injection+vulnerability+in+Superfecta+Module), [link 2](https://wiki.freepbx.org/display/FOP/List+of+Securities+Vulnerabilities).