CVE-2019-19852: XSS
Published Mar 16, 2020
·Updated
An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report screen in the cel module at the admin/config.php?display=cel URI via date fields. This affects cel through 13.0.26.9, 14.x through 14.0.2.14, and 15.x through 15.0.15.4.
Affected Software
3 affected components
Sangoma FreePBX >=13.0<=13.0.26.9
Sangoma FreePBX >=14.0<=14.0.2.14
Sangoma FreePBX >=15.0<=15.0.15.4
Event History
Mar 16, 2020
CVE Published
via MITRE·08:36 PM
Data Sourced
via MITRE·08:36 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-19852.
2
What is the severity of CVE-2019-19852?
The severity of CVE-2019-19852 is medium (4.8).
3
Which software versions are affected by CVE-2019-19852?
Sangoma FreePBX and PBXact versions 13, 14, and 15 are affected.
4
How does CVE-2019-19852 impact the system?
CVE-2019-19852 allows an attacker to inject XSS code through the Call Event Logging report screen in the cel module.
5
How can I fix CVE-2019-19852?
Update to the latest versions of Sangoma FreePBX and PBXact to mitigate CVE-2019-19852.