#VU22288 Information disclosure in FusionPBX - CVE-2019-11407

 

#VU22288 Information disclosure in FusionPBX - CVE-2019-11407

Published: October 25, 2019


Vulnerability identifier: #VU22288
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-11407
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
FusionPBX
Software vendor:
FusionPBX

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists in the "app/operator_panel/index_inc.php" file in the Operator Panel due to the debug parameter dumps the contents of several arrays, most notably the $_SESSION array. A remote authenticated administrator can gain unauthorized access to sensitive information on the system, such as the password for the FreeSWITCH event socket interface.


Remediation

Install updates from vendor's website.

External links