PhoneSystem Terminal in 3CX Phone System (Debian based...
High severity
Unreviewed
Published
Jun 8, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jun 7, 2022
Published to the GitHub Advisory Database
Jun 8, 2022
Last updated
Jan 27, 2023
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges because of " followed by " mishandling.
References