Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2019-13176

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

3CX Phone system(web)management console是一款基于Web的3CX电话系统管理控制台程序。 3CX Phone system (web) management console 12.5.44178.1002版本至12.5 SP2版本中存在代码问题漏洞。该漏洞源于网络系统或产品的代码开发过程中存在设计或实现不当的问题。

AI Predicted 8.6 Difficulty: Moderate EPSS 2.46% · P83
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2019-13176

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST data. There is potential to use this for SSRF (reading local files, outbound HTTP, and outbound DNS).
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
3CX Phone system(web)management console 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
3CX Phone system(web)management console是一款基于Web的3CX电话系统管理控制台程序。 3CX Phone system (web) management console 12.5.44178.1002版本至12.5 SP2版本中存在代码问题漏洞。该漏洞源于网络系统或产品的代码开发过程中存在设计或实现不当的问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2019-13176

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-13176

登录查看更多情报信息。

Security Blog Posts for CVE-2019-13176 (1)

Same Patch Batch · n/a · 2019-08-08 · 35 CVEs total

CVE-2016-10864 NETGEAR EX7000 跨站脚本漏洞
CVE-2019-14774 WordPress woo-variation-swatches插件跨站脚本漏洞
CVE-2019-14353 Trezor One 信息泄露漏洞
CVE-2019-12959 ZOHO ManageEngine AssetExplorer 代码问题漏洞
CVE-2019-12994 ZOHO ManageEngine AssetExplorer 代码问题漏洞
CVE-2019-14693 ZOHO ManageEngine AssetExplorer 代码问题漏洞
CVE-2019-14335 D-Link 6600-AP和DWL-3600AP 授权问题漏洞
CVE-2019-14772 verdaccio 跨站脚本漏洞
CVE-2018-19855 UiPath Orchestrator 输入验证错误漏洞
CVE-2019-14773 WordPress Woody ad snippets插件安全特征问题漏洞
CVE-2019-14255 go-camo 代码问题漏洞
CVE-2019-14221 1CRM Systems 1CRM On-Premise Software 跨站脚本漏洞
CVE-2019-14754 Open-School SQL注入漏洞
CVE-2019-13101 D-Link DIR-600M 访问控制错误漏洞
CVE-2019-14769 Backdrop CMS 跨站脚本漏洞
CVE-2019-14770 Backdrop CMS 跨站脚本漏洞
CVE-2019-14771 Backdrop CMS 输入验证错误漏洞
CVE-2016-10863 Edimax Wi-Fi Extender 跨站请求伪造漏洞
CVE-2016-10862 Neet AirStream NAS1.1 跨站请求伪造漏洞
CVE-2018-20954 Mailpile 授权问题漏洞

Showing top 20 of 35 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2019-13176

No comments yet


Leave a comment