CVE-2021-43406: Input Validation
Published Nov 5, 2021
·Updated
An issue was discovered in FusionPBX before 4.5.30. The faxpostsize may have risky characters (it is not constrained to preset values).
Affected Software
1 affected component
FusionPBX Fusionpbx<4.5.30
Remediation
Event History
Nov 5, 2021
CVE Published
via MITRE·05:36 PM
Data Sourced
via MITRE·05:36 PM
Description
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-43406?
CVE-2021-43406 has a medium severity rating due to potential risks associated with unvalidated input.
2
How do I fix CVE-2021-43406?
To fix CVE-2021-43406, update FusionPBX to version 4.5.30 or later.
3
What types of characters can cause issues in CVE-2021-43406?
CVE-2021-43406 may allow risky characters in the fax_post_size that are not properly constrained.
4
Which versions of FusionPBX are affected by CVE-2021-43406?
CVE-2021-43406 affects all versions of FusionPBX prior to 4.5.30.
5
What are the potential impacts of exploiting CVE-2021-43406?
Exploiting CVE-2021-43406 can lead to security vulnerabilities including possible injection attacks.