Improper access control in FusionPBX - CVE-2019-16986

 

Improper access control in FusionPBX - CVE-2019-16986

Published: October 23, 2019


Vulnerability identifier: #VU22208
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-16986
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the application allows an attacker to download arbitrary file from the system passed via the "f" HTTP parameter to "/resources/download.php" or "/resources/secure_download.php" scripts. A remote authenticated user can pass a full filename to the application and download arbitrary file from the server using directory traversal sequences.


Affected software

FusionPBX

How to mitigate CVE-2019-16986

Install updates from vendor's repository.


External References

Related Security Bulletins