CVE-2019-11407
Summary
| CVE | CVE-2019-11407 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-17 18:15:00 UTC |
| Updated | 2019-06-18 20:15:00 UTC |
| Description | app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to excessive debug information, which allows authenticated administrative attackers to obtain credentials and other sensitive information. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Update index_inc.php · fusionpbx/fusionpbx@f38676b · GitHub | MISC | github.com | Patch, Third Party Advisory |
| GDS - Blog - RCE Using Caller ID - Multiple Vulnerabilities in FusionPBX | MISC | blog.gdssecurity.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.