Vulnerability Description
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation that allows authenticated non-administrative attackers to execute commands on the host. This can further lead to remote code execution when combined with an XSS vulnerability also present in the FusionPBX Operator Panel module.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fusionpbx | Fusionpbx | 4.4.3 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/153256/FusionPBX-4.4.3-Remote-Command-ExecuExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/155344/FusionPBX-Operator-Panel-exec.php-CoExploitThird Party AdvisoryVDB Entry
- https://blog.gdssecurity.com/labs/2019/6/7/rce-using-caller-id-multiple-vulnerabExploitThird Party Advisory
- https://github.com/fusionpbx/fusionpbx/commit/e43ca27ba2d9c0109a6bf198fe2f8d79f6PatchThird Party Advisory
- http://packetstormsecurity.com/files/153256/FusionPBX-4.4.3-Remote-Command-ExecuExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/155344/FusionPBX-Operator-Panel-exec.php-CoExploitThird Party AdvisoryVDB Entry
- https://blog.gdssecurity.com/labs/2019/6/7/rce-using-caller-id-multiple-vulnerabExploitThird Party Advisory
- https://github.com/fusionpbx/fusionpbx/commit/e43ca27ba2d9c0109a6bf198fe2f8d79f6PatchThird Party Advisory
FAQ
What is CVE-2019-11409?
CVE-2019-11409 is a vulnerability with a CVSS score of 8.8 (HIGH). app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation that allows authenticated non-administrativ...
How severe is CVE-2019-11409?
CVE-2019-11409 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-11409?
Check the references section above for vendor advisories and patch information. Affected products include: Fusionpbx Fusionpbx.