Vulnerabilities > Sangoma > Freepbx > 15.0.13.7
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-11-02 | CVE-2023-43336 | Unspecified vulnerability in Sangoma Freepbx Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing extension=self to extension=101. | 8.8 |
2020-03-16 | CVE-2019-19852 | Cross-site Scripting vulnerability in Sangoma Freepbx An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report screen in the cel module at the admin/config.php?display=cel URI via date fields. | 4.8 |
2019-12-06 | CVE-2019-19552 | Cross-site Scripting vulnerability in Sangoma Freepbx In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the user management screen of the Administrator web site, i.e., the/admin/config.php?display=userman URI. | 4.8 |
2019-12-06 | CVE-2019-19551 | Cross-site Scripting vulnerability in Sangoma Freepbx In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the User Management screen of the Administrator web site. | 4.8 |
2019-11-21 | CVE-2019-19006 | Improper Authentication vulnerability in Sangoma Freepbx Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control. | 9.8 |