This issue affects CompletePBX: all versions up to and prior to 5.2.35
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 27 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 23 Sep 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xorcom
Xorcom completepbx |
|
| CPEs | cpe:2.3:a:xorcom:completepbx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xorcom
Xorcom completepbx |
Mon, 31 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Mar 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Xorcom CompletePBX is vulnerable to command injection in the administrator Task Scheduler functionality, allowing for attackers to execute arbitrary commands as the root user. This issue affects CompletePBX: all versions up to and prior to 5.2.35 | |
| Title | Xorcom CompletePBX <= 5.2.35 Task Scheduler Authenticated Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-27T16:47:39.968Z
Reserved: 2025-03-13T17:27:08.113Z
Link: CVE-2025-30004
Updated: 2025-03-31T18:50:21.446Z
Status : Modified
Published: 2025-03-31T17:15:41.737
Modified: 2025-12-27T17:15:47.593
Link: CVE-2025-30004
No data.
OpenCVE Enrichment
No data.