Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/RecordingList/DownloadRecord?file=" and "/api/SupportInfo?file=" are the vulnerable parameters. An attacker must be authenticated to exploit this issue to access sensitive information to aid in subsequent attacks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
3CX Phone System Management Console 路径遍历漏洞
Vulnerability Description
3CX Phone System是一套包括网络会议、IP电话和手机客户端的统一通信解决方案。Management Console是其中的一个管理控制台程序。 3CX Phone System 15.5.3554.1版本中的Management Console存在目录遍历漏洞。攻击者可借助‘/api/RecordingList/DownloadRecord?file=’和‘/api/RecordingList/DownloadRecord?file=’参数利用该漏洞访问敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A