Vulnerabilities (CVE)

Filtered by vendor 3cx Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-14907 1 3cx 1 3cx Web Server 2020-08-24 5.0 MEDIUM 5.3 MEDIUM
The Web server in 3CX version 15.5.8801.3 is vulnerable to Information Leakage, because of improper error handling in Stack traces, as demonstrated by discovering a full pathname.
CVE-2018-14906 1 3cx 1 3cx Web Server 2018-09-26 4.3 MEDIUM 6.1 MEDIUM
The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on all stack traces' propertyPath parameters.
CVE-2018-14905 1 3cx 1 3cx Web Server 2018-09-26 4.3 MEDIUM 6.1 MEDIUM
The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on the api/CallLog TimeZoneName parameter.
CVE-2018-7654 1 3cx 1 3cx 2018-03-28 4.0 MEDIUM 6.5 MEDIUM
On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access to files on the server via path traversal.
CVE-2017-15359 1 3cx 1 3cx 2017-11-13 4.0 MEDIUM 6.5 MEDIUM
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/RecordingList/DownloadRecord?file=" and "/api/SupportInfo?file=" are the vulnerable parameters. An attacker must be authenticated to exploit this issue to access sensitive information to aid in subsequent attacks.