A vulnerability was found in FreeBPX voicemail. It has been rated as problematic. Affected by this issue is some unknown functionality of the file views/ssettings.php of the component Settings Handler. The manipulation of the argument key leads to cross site scripting. The attack may be launched remotely. Upgrading to version 14.0.6.25 is able to address this issue. The name of the patch is ffce4882016076acd16fe0f676246905aa3cb2f3. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216872.
References
Link | Resource |
---|---|
https://github.com/FreePBX/voicemail/commit/ffce4882016076acd16fe0f676246905aa3cb2f3 | Patch Third Party Advisory |
https://github.com/FreePBX/voicemail/releases/tag/release%2F14.0.6.25 | Release Notes Third Party Advisory |
https://vuldb.com/?ctiid.216872 | Third Party Advisory |
https://vuldb.com/?id.216872 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: VulDB
Published: 2022-12-27T09:46:16.138Z
Updated:
Reserved: 2022-12-27T09:44:54.936Z
Link: CVE-2021-4283
JSON object: View
NVD Information
Status : Modified
Published: 2022-12-27T10:15:11.620
Modified: 2024-05-17T02:03:31.690
Link: CVE-2021-4283
JSON object: View
Redhat Information
No data.
CWE