An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Superfecta module at the admin/config.php?display=superfecta URI. This affects Superfecta through 13.0.4.7, 14.x through 14.0.24, and 15.x through 15.0.2.20.
2020-03-16T16:15:12.110
2024-11-21T04:35:31.860
Modified
CVSSv3.1: 4.8 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sangoma | freepbx | ≤ 13.0.4.7 | Yes |
Application | sangoma | freepbx | ≤ 14.0.24 | Yes |
Application | sangoma | freepbx | ≤ 15.0.2.20 | Yes |