This issue affects CompletePBX: all versions up to and prior to 5.2.35
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 27 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 23 Sep 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xorcom
Xorcom completepbx |
|
| CPEs | cpe:2.3:a:xorcom:completepbx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xorcom
Xorcom completepbx |
Mon, 31 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Mar 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any retrieved file in place of the expected report. This issue affects CompletePBX: all versions up to and prior to 5.2.35 | |
| Title | Xorcom CompletePBX <= 5.2.35 Authenticated Path Traversal & File Deletion | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-27T16:47:40.395Z
Reserved: 2025-03-13T17:27:08.113Z
Link: CVE-2025-30005
Updated: 2025-03-31T18:47:08.777Z
Status : Modified
Published: 2025-03-31T17:15:41.880
Modified: 2025-12-27T17:15:47.760
Link: CVE-2025-30005
No data.
OpenCVE Enrichment
No data.