#VU22288 Information disclosure in FusionPBX - CVE-2019-11407
Published: October 25, 2019
FusionPBX
FusionPBX
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists in the "app/operator_panel/index_inc.php" file in the Operator Panel due to the debug parameter dumps the contents of several arrays, most notably the $_SESSION array. A remote authenticated administrator can gain unauthorized access to sensitive information on the system, such as the password for the FreeSWITCH event socket interface.