CVE-2018-7654

On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access to files on the server via path traversal.
Configurations

Configuration 1

cpe:2.3:a:3cx:3cx:15.5.6354.2:*:*:*:*:*:*:*

Information

Published : 2018-03-04 01:29

Updated : 2018-03-28 10:00


NVD link : CVE-2018-7654

Mitre link : CVE-2018-7654

Products Affected
No products.
CWE