Xorcom CompletePBX is vulnerable to a reflected cross-site scripting (XSS) in the administrative control panel. This issue affects CompletePBX: all versions up to and prior to 5.2.35
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://vulncheck.com/advisories/completepbx-reflected-xss | third party advisory |
https://www.xorcom.com/new-completepbx-release-5-2-36-1/ | vendor advisory |