Vulnerability Description
An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4. By crafting a request for adding Asterisk modules, an attacker is able to store JavaScript commands in a module name.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freepbx | Freepbx | 15.0.1 |
| Sangoma | Freepbx | < 13.0.122.43 |
Related Weaknesses (CWE)
References
- https://wiki.freepbx.org/display/FOP/2018-09-11+Core+Stored+XSS?src=contextnavpaVendor Advisory
- https://www.freepbx.org/Product
- https://wiki.freepbx.org/display/FOP/2018-09-11+Core+Stored+XSS?src=contextnavpaVendor Advisory
- https://www.freepbx.org/Product
FAQ
What is CVE-2018-15891?
CVE-2018-15891 is a vulnerability with a CVSS score of 4.8 (MEDIUM). An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4. By crafting a request for adding Asterisk modules, an attacker is able to store JavaScript commands in a module n...
How severe is CVE-2018-15891?
CVE-2018-15891 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-15891?
Check the references section above for vendor advisories and patch information. Affected products include: Freepbx Freepbx, Sangoma Freepbx.