Vulnerabilities > Netfortris > Trixbox > 1.2.0

DATE CVE VULNERABILITY TITLE RISK
2020-05-01 CVE-2020-7351 OS Command Injection vulnerability in Netfortris Trixbox 1.2.0/2.8.0.4
An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user.
network
low complexity
netfortris CWE-78
critical
9.0