CVE-2024-23387: XSS
Published Jan 19, 2024
·Updated
FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is logging in to the product.
Affected Software
1 affected component
FusionPBX Fusionpbx<5.1.0
Event History
Jan 19, 2024
CVE Published
via MITRE·03:47 AM
Data Sourced
via MITRE·03:47 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23387?
CVE-2024-23387 has a medium severity rating due to its potential for exploitation by authenticated remote attackers.
2
How do I fix CVE-2024-23387?
To fix CVE-2024-23387, upgrade FusionPBX to version 5.1.0 or later.
3
Who is affected by CVE-2024-23387?
CVE-2024-23387 affects all versions of FusionPBX prior to 5.1.0.
4
What type of vulnerability is CVE-2024-23387?
CVE-2024-23387 is a cross-site scripting vulnerability.
5
Can CVE-2024-23387 be exploited remotely?
Yes, CVE-2024-23387 can be exploited by a remote attacker with administrative privileges.