VulnerabilityModified
CVE-2019-16986
In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname and allows a download of it.
MEDIUM 6.5EPSS 1.41%
Does this matter?
Lower severity and a low EPSS score (1.41%). Track it; it rarely justifies an emergency change on its own.
Description
In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname and allows a download of it. (resources\secure_download.php is also affected.)
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.41% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- fusionpbx/fusionpbx
- Source
- cve@mitre.org
References
- https://github.com/fusionpbx/fusionpbx/commit/9482d9ee0e4287df21339be4276125e38e048951Not Applicable
- https://github.com/fusionpbx/fusionpbx/commit/9c61191049c949e01f99ea1fbab1feb44709e108Not Applicable
- https://resp3ctblog.wordpress.com/2019/10/19/fusionpbx-path-traversal-2/Third Party Advisory
- https://github.com/fusionpbx/fusionpbx/commit/9482d9ee0e4287df21339be4276125e38e048951Not Applicable
- https://github.com/fusionpbx/fusionpbx/commit/9c61191049c949e01f99ea1fbab1feb44709e108Not Applicable
- https://resp3ctblog.wordpress.com/2019/10/19/fusionpbx-path-traversal-2/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.