Beveiligingsadvies

CVE-2018-7654

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2018-03-04 01:00:00
Laatst bijgewerkt 2024-09-17 02:42:38
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access to files on the server via path traversal.