CVE-2019-16981 is a Cross-Site Scripting (XSS) vulnerability affecting FusionPBX up to version 4.5.7, where an unsanitized "id" variable from the URL is reflected in HTML. With a CVSS score of 6.1 (Medium), this vulnerability requires user interaction (UI:R) and can lead to low impact on confidentiality and integrity (C:L/I:L) through network-based attacks (AV:N). There is no evidence of active exploitation, publicly available exploit code in Metasploit or ExploitDB, nor significant community discussion or media coverage, indicating a low current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.5.7CPE matchmatch criteria | cpe:2.3:a:fusionpbx:fusionpbx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.