An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report screen in the cel module at the admin/config.php?display=cel URI via date fields. This affects cel through 13.0.26.9, 14.x through 14.0.2.14, and 15.x through 15.0.15.4.
2020-03-16T21:15:12.390
2024-11-21T04:35:32.000
Modified
CVSSv3.1: 4.8 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sangoma | freepbx | ≤ 13.0.26.9 | Yes |
Application | sangoma | freepbx | ≤ 14.0.2.14 | Yes |
Application | sangoma | freepbx | ≤ 15.0.15.4 | Yes |