CVE-2019-19851: XSS
An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Superfecta module at the admin/config.php?display=superfecta URI. This affects Superfecta through 13.0.4.7, 14.x through 14.0.24, and 15.x through 15.0.2.20.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19851?
CVE-2019-19851 is an XSS Injection vulnerability that exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Superfecta module.
What software versions are affected by CVE-2019-19851?
Sangoma FreePBX versions 13.0.4.7, 14.x (up to 14.0.24), and 15.x (up to 15.0.2.20) are affected.
How severe is CVE-2019-19851?
CVE-2019-19851 has a severity rating of 4.8, which is considered medium.
How can I fix CVE-2019-19851?
To fix CVE-2019-19851, it is recommended to update to the latest version of Sangoma FreePBX and PBXact.
Where can I find more information about CVE-2019-19851?
More information about CVE-2019-19851 can be found in the references provided: [link 1](https://wiki.freepbx.org/display/FOP/2020-01-09+XSS+Injection+vulnerability+in+Superfecta+Module), [link 2](https://wiki.freepbx.org/display/FOP/List+of+Securities+Vulnerabilities).