Vulnerabilities (CVE)

Filtered by vendor 3cx Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-49954 1 3cx 1 3cx 2024-01-03 N/A 9.8 CRITICAL
The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address.
CVE-2022-28005 1 3cx 1 3cx 2022-05-18 5.0 MEDIUM 9.8 CRITICAL
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrary files on the server, leading to cleartext credential disclosure. Afterwards, the authenticated attacker is able to upload a file that overwrites a 3CX service binary, leading to Remote Code Execution as NT AUTHORITY\SYSTEM on Windows installations. Versions prior to version 18, Hotfix 1 Build 18.0.3.461 March 2022, are prone to an additional unauthenticated file system access to C:\Windows\System32.
CVE-2019-12498 1 3cx 1 Live Chat 2021-08-12 7.5 HIGH 9.8 CRITICAL
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.
CVE-2018-12426 1 3cx 1 Live Chat 2021-07-20 7.5 HIGH 9.8 CRITICAL
The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation of allowed file types, as demonstrated by a v1/remote_upload request with a .php filename and the image/jpeg content type.