Total vulnerabilities in the database
An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for FreePBX 14.0.10.3. In the Contactmanager class (html\admin\modules\contactmanager\Contactmanager.class.php), an unsanitized group variable coming from the URL is reflected in HTML on 2 occasions, leading to XSS. It can be requested via a GET request to /admin/ajax.php?module=contactmanager.
Software | From | Fixed in |
---|---|---|
freepbx / contactmanager | 13.0.0-beta1 | 13.0.0-beta1.x |
freepbx / contactmanager | 13.0.0-beta2 | 13.0.0-beta2.x |
freepbx / contactmanager | 13.0.0-beta3 | 13.0.0-beta3.x |
freepbx / contactmanager | 13.0.0-beta4 | 13.0.0-beta4.x |
freepbx / contactmanager | 13.0.0-beta5 | 13.0.0-beta5.x |
freepbx / contactmanager | 13.0.2 | 13.0.45.3 |
freepbx / contactmanager | 14.0.1 | 14.0.1.x |
freepbx / contactmanager | 14.0.1-alpha1 | 14.0.1-alpha1.x |
freepbx / contactmanager | 14.0.1-alpha2 | 14.0.1-alpha2.x |
freepbx / contactmanager | 14.0.1-beta1 | 14.0.1-beta1.x |
freepbx / contactmanager | 14.0.1-beta2 | 14.0.1-beta2.x |
freepbx / contactmanager | 14.0.1-beta3 | 14.0.1-beta3.x |
freepbx / contactmanager | 14.0.1.1 | 14.0.5.12 |
freepbx / contactmanager | 15.0.2 | 15.0.8.21 |
sangoma / freepbx | 14.0.10.3 | 14.0.10.3.x |