Security Advisory

CVE-2017-15359

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-10-18 18:00:00
Last updated 2024-08-05 19:57:25
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/RecordingList/DownloadRecord?file=" and "/api/SupportInfo?file=" are the vulnerable parameters. An attacker must be authenticated to exploit this issue to access sensitive information to aid in subsequent attacks.