SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-16967

In the Manager module form (html\admin\modules\manager\views\form.php), an unsanitized managerdisplay variable coming from the URL is reflected in HTML, leading to XSS.

MEDIUM 6.1EPSS 1.31%

Does this matter?

Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager module form (html\admin\modules\manager\views\form.php), an unsanitized managerdisplay variable coming from the URL is reflected in HTML, leading to XSS. It can be requested via GET request to /config.php?type=tool&display=manager.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
1.31% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
freepbx/manager · sangoma/freepbx
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.