app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation that allows authenticated non-administrative attackers to execute commands on the host. This can further lead to remote code execution when combined with an XSS vulnerability also present in the FusionPBX Operator Panel module.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-06-17T18:02:23

Updated: 2024-08-04T22:55:40.800Z

Reserved: 2019-04-21T00:00:00

Link: CVE-2019-11409

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-06-17T19:15:11.327

Modified: 2022-04-18T17:16:57.080

Link: CVE-2019-11409

cve-icon Redhat

No data.