Перейти к содержимому
Noroxi

Записи 3CX

34 опубликованных записей вендора 3cx.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
3
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Охват bug bounty

Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.

Все записи

34 записей
  • CVE-2022-28005
    41В плане

    An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL.

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    3cx · 3cx6 мая 2022 г.

  • CVE-2018-12426
    41В плане

    The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side va

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    3cx · live chat2 июл. 2018 г.

  • CVE-2019-11185
    40В плане

    The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    3cx · live chat3 июн. 2019 г.

  • CVE-2023-49954
    40В плане

    The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address

    КритическаяCVSS 9,8Proof of conceptEPSS 2 %

    3cx · 3cx25 дек. 2023 г.

  • CVE-2019-12498
    40В плане

    The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check pr

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    3cx · live chat20 мар. 2020 г.

  • CVE-2019-9972
    36Наблюдать

    PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    3cx · phone system firmware7 июн. 2022 г.

  • CVE-2019-9971
    36Наблюдать

    PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo wi

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    3cx · phone system firmware7 июн. 2022 г.

  • CVE-2021-45490
    36Наблюдать

    The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    3cx · 3cx27 мар. 2022 г.

  • CVE-2022-27438
    33Наблюдать

    Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affect

    ВысокаяCVSS 8,1Proof of conceptEPSS 2 %

    caphyon · advanced installer6 июн. 2022 г.

  • CVE-2023-29059
    32Наблюдать

    3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 4 %

    3cx · 3cx30 мар. 2023 г.

  • CVE-2019-13176
    31Наблюдать

    An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    3cx · 3cx8 авг. 2019 г.

  • CVE-2022-48482
    31Наблюдать

    3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electr

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    3cx · 3cx2 мая 2023 г.

  • CVE-2022-48483
    31Наблюдать

    3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/dow

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    3cx · 3cx2 мая 2023 г.

  • CVE-2008-6895
    31Наблюдать

    3CX Phone System 6.0.806.0 allows remote attackers to cause a denial of service (unstable service or crash) via unspecified vectors, as demo

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    3cx · phone system3 авг. 2009 г.

  • CVE-2023-27362
    31Наблюдать

    3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    3cx · 3cx2 мая 2024 г.

  • CVE-2019-14935
    31Наблюдать

    3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    3cx · 3cx11 авг. 2019 г.

  • CVE-2017-15359
    28Наблюдать

    In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/a

    СредняяCVSS 6,5Proof of conceptEPSS 6 %

    3cx · 3cx18 окт. 2017 г.

  • CVE-2018-7654
    27Наблюдать

    On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access to files on the serve

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    3cx · 3cx3 мар. 2018 г.

  • CVE-2021-45491
    26Наблюдать

    3CX System through 2022-03-17 stores cleartext passwords in a database.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    3cx · 3cx27 мар. 2022 г.

  • CVE-2019-9913
    24Наблюдать

    The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    3cx · live chat21 мар. 2019 г.

  • CVE-2018-9864
    24Наблюдать

    The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    3cx · live chat9 апр. 2018 г.

  • CVE-2017-2187
    24Наблюдать

    Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arbitrary web script or

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    3cx · live chat9 июн. 2017 г.

  • CVE-2019-14950
    24Наблюдать

    The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    3cx · live chat12 авг. 2019 г.

  • CVE-2018-11105
    24Наблюдать

    There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "emai

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    3cx · live chat15 мая 2018 г.

  • CVE-2018-18460
    24Наблюдать

    XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivech

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    3cx · live chat18 окт. 2018 г.