Vulnerabilities > 3CX > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-12-25 CVE-2023-49954 SQL Injection vulnerability in 3CX
The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address.
network
low complexity
3cx CWE-89
critical
9.8
2022-06-07 CVE-2019-9971 Improper Privilege Management vulnerability in multiple products
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tcpdump command, without a password.
network
low complexity
3cx debian CWE-269
critical
9.0
2022-06-07 CVE-2019-9972 Command Injection vulnerability in multiple products
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges because of "<space><space> followed by <shift><enter>" mishandling.
network
low complexity
3cx debian CWE-77
critical
9.0
2022-05-06 CVE-2022-28005 Insufficiently Protected Credentials vulnerability in 3CX
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL.
network
low complexity
3cx CWE-522
critical
9.8
2019-06-03 CVE-2019-11185 Unrestricted Upload of File with Dangerous Type vulnerability in 3CX Live Chat
The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability.
network
low complexity
3cx CWE-434
critical
9.8