CVE-2019-16967
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager module form (html\admin\modules\manager\views\form.php), an unsanitized managerdisplay variable coming from the URL is reflected in HTML, leading to XSS. It can be requested via GET request to /config.php?type=tool&display=manager.
Se detectó un problema en Manager versiones 13.x anteriores a 13.0.2.6 y versiones 15.x anteriores a 15.0.6 antes del FreePBX versión 14.0.10.3. En el formulario module de Manager (archivo html\admin\modules\manager\views\form.php), una variable managerdisplay no saneada que proviene de la URL es reflejada en HTML, conllevando a una vulnerabilidad de tipo XSS. Que puede ser solicitada mediante una petición GET en /config.php?type=tool&display=manager.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-09-29 CVE Reserved
- 2019-10-21 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-10-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://issues.freepbx.org/browse/FREEPBX-20436 | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://github.com/FreePBX/manager/commit/071a50983ca6a373bb2d1d3db68e9eda4667a372 | 2019-12-10 | |
https://resp3ctblog.wordpress.com/2019/10/19/freepbx-xss-2 | 2019-12-10 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Freepbx Search vendor "Freepbx" | Manager Search vendor "Freepbx" for product "Manager" | >= 13.0.2 < 13.0.2.6 Search vendor "Freepbx" for product "Manager" and version " >= 13.0.2 < 13.0.2.6" | - |
Affected
| ||||||
Freepbx Search vendor "Freepbx" | Manager Search vendor "Freepbx" for product "Manager" | >= 15.0.2 < 15.0.6 Search vendor "Freepbx" for product "Manager" and version " >= 15.0.2 < 15.0.6" | - |
Affected
| ||||||
Freepbx Search vendor "Freepbx" | Manager Search vendor "Freepbx" for product "Manager" | 13.0.1 Search vendor "Freepbx" for product "Manager" and version "13.0.1" | alpha1 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Freepbx Search vendor "Sangoma" for product "Freepbx" | < 14.0.10.3 Search vendor "Sangoma" for product "Freepbx" and version " < 14.0.10.3" | - |
Affected
|