#VU22254 Improper access control in FusionPBX - CVE-2019-16990
Published: October 24, 2019
FusionPBX
FusionPBX
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in app/music_on_hold/music_on_hold.php file when processing base64-encoded file names. A remote authenticated user can pass a base64-encoded filename to the application and download any pathname on the system.