Avantfax is a fax-to-email gateway and unified communications platform whose vulnerability footprint centers on a single, modestly deployed product with a consistent pattern of web-application and file-handling weaknesses. The recurring exposure involves cross-site scripting, OS command injection, unrestricted file uploads, and information-disclosure flaws typical of server-facing communication appliances, alongside a tendency toward direct user input processing in web interfaces. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Avantfax over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-18024MEDIUM AvantFAX 3.3.3 has XSS via an arbitrary parameter name to the default URI, as demonstrated by a parameter whose name contains a SCRIPT element and whose value is 1. | Jan 10, 2018 | 6.1 | 31 | NO | YES |
CVE-2020-11766HIGH sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection. | May 19, 2020 | 8.8 | 28 | NO | NO |
CVE-2023-23328HIGH A File Upload vulnerability exists in AvantFAX 3.3.7. An authenticated user can bypass PHP file type validation in FileUpload.php by uploading a specially crafted PHP file. | Mar 10, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-23327MEDIUM An Information Disclosure vulnerability exists in AvantFAX 3.3.7. Backups of the AvantFAX sent/received faxes, and database backups are stored using the current date as the filenam | Mar 10, 2023 | 4.9 | 21 | NO | NO |
CVE-2023-23326MEDIUM A Stored Cross-Site Scripting (XSS) vulnerability exists in AvantFAX 3.3.7. An authenticated low privilege user can inject arbitrary Javascript into their e-mail address which is e | Mar 10, 2023 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Avantfax.
Media articles that mention a CVE ID that affects a product developed by Avantfax — matched by CVE ID, not by vendor name.