Записи 3CX
34 опубликованных записей вендора 3cx.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-295 Improper Certificate Validation1
- CWE-427 Uncontrolled Search Path Element1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
34 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2022-28005Эксплойта нет | An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL.3cx · 3cx · CWE-522 | Критическая9,8 | — | 6,7 % | 6 мая 2022 г. |
41В плане | CVE-2018-12426Эксплойта нет | The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side va3cx · live chat · CWE-434 | Критическая9,8 | — | 5,1 % | 2 июл. 2018 г. |
40В плане | CVE-2019-11185Эксплойта нет | The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability.3cx · live chat · CWE-434 | Критическая9,8 | — | 4,3 % | 3 июн. 2019 г. |
40В плане | CVE-2023-49954Proof of concept | The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address3cx · 3cx · CWE-89 | Критическая9,8 | — | 2,2 % | 25 дек. 2023 г. |
40В плане | CVE-2019-12498Эксплойта нет | The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check pr3cx · live chat · CWE-862 | Критическая9,8 | — | 2,0 % | 20 мар. 2020 г. |
36Наблюдать | CVE-2019-9972Эксплойта нет | PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands 3cx · phone system firmware · CWE-77 | Высокая8,8 | — | 1,7 % | 7 июн. 2022 г. |
36Наблюдать | CVE-2019-9971Эксплойта нет | PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo wi3cx · phone system firmware · CWE-269 | Высокая8,8 | — | 1,7 % | 7 июн. 2022 г. |
36Наблюдать | CVE-2021-45490Эксплойта нет | The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate 3cx · 3cx · CWE-295 | Критическая9,1 | — | 1,1 % | 27 мар. 2022 г. |
33Наблюдать | CVE-2022-27438Proof of concept | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affectcaphyon · advanced installer · CWE-494 | Высокая8,1 | — | 2,0 % | 6 июн. 2022 г. |
32Наблюдать | CVE-2023-29059Эксплойта нет | 3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023.3cx · 3cx | Высокая7,8 | — | 4,4 % | 30 мар. 2023 г. |
31Наблюдать | CVE-2019-13176Эксплойта нет | An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2.3cx · 3cx · CWE-611 | Высокая7,5 | — | 2,5 % | 8 авг. 2019 г. |
31Наблюдать | CVE-2022-48482Эксплойта нет | 3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electr3cx · 3cx · CWE-22 | Высокая7,5 | — | 1,8 % | 2 мая 2023 г. |
31Наблюдать | CVE-2022-48483Эксплойта нет | 3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/dow3cx · 3cx · CWE-22 | Высокая7,5 | — | 1,7 % | 2 мая 2023 г. |
31Наблюдать | CVE-2008-6895Эксплойта нет | 3CX Phone System 6.0.806.0 allows remote attackers to cause a denial of service (unstable service or crash) via unspecified vectors, as demo3cx · phone system | Высокая7,8 | — | 1,2 % | 3 авг. 2009 г. |
31Наблюдать | CVE-2023-27362Эксплойта нет | 3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability3cx · 3cx · CWE-427 | Высокая7,8 | — | 0,4 % | 2 мая 2024 г. |
31Наблюдать | CVE-2019-14935Эксплойта нет | 3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full 3cx · 3cx · CWE-732 | Высокая7,8 | — | 0,4 % | 11 авг. 2019 г. |
28Наблюдать | CVE-2017-15359Proof of concept | In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/a3cx · 3cx · CWE-22 | Средняя6,5 | — | 6,2 % | 18 окт. 2017 г. |
27Наблюдать | CVE-2018-7654Эксплойта нет | On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access to files on the serve3cx · 3cx · CWE-22 | Средняя6,5 | — | 2,4 % | 3 мар. 2018 г. |
26Наблюдать | CVE-2021-45491Эксплойта нет | 3CX System through 2022-03-17 stores cleartext passwords in a database.3cx · 3cx · CWE-312 | Средняя6,5 | — | 0,8 % | 27 мар. 2022 г. |
24Наблюдать | CVE-2019-9913Эксплойта нет | The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.3cx · live chat · CWE-79 | Средняя6,1 | — | 1,4 % | 21 мар. 2019 г. |
24Наблюдать | CVE-2018-9864Эксплойта нет | The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.3cx · live chat · CWE-79 | Средняя6,1 | — | 1,3 % | 9 апр. 2018 г. |
24Наблюдать | CVE-2017-2187Эксплойта нет | Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arbitrary web script or3cx · live chat · CWE-79 | Средняя6,1 | — | 1,3 % | 9 июн. 2017 г. |
24Наблюдать | CVE-2019-14950Proof of concept | The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.3cx · live chat · CWE-79 | Средняя6,1 | — | 1,2 % | 12 авг. 2019 г. |
24Наблюдать | CVE-2018-11105Эксплойта нет | There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "emai3cx · live chat · CWE-79 | Средняя6,1 | — | 1,1 % | 15 мая 2018 г. |
24Наблюдать | CVE-2018-18460Эксплойта нет | XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivech3cx · live chat · CWE-79 | Средняя6,1 | — | 1,0 % | 18 окт. 2018 г. |
- CVE-2022-2800541В плане
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %3cx · 3cx6 мая 2022 г.
- CVE-2018-1242641В плане
The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side va
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %3cx · live chat2 июл. 2018 г.
- CVE-2019-1118540В плане
The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %3cx · live chat3 июн. 2019 г.
- CVE-2023-4995440В плане
The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address
КритическаяCVSS 9,8Proof of conceptEPSS 2 %3cx · 3cx25 дек. 2023 г.
- CVE-2019-1249840В плане
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check pr
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %3cx · live chat20 мар. 2020 г.
- CVE-2019-997236Наблюдать
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %3cx · phone system firmware7 июн. 2022 г.
- CVE-2019-997136Наблюдать
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo wi
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %3cx · phone system firmware7 июн. 2022 г.
- CVE-2021-4549036Наблюдать
The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %3cx · 3cx27 мар. 2022 г.
- CVE-2022-2743833Наблюдать
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affect
ВысокаяCVSS 8,1Proof of conceptEPSS 2 %caphyon · advanced installer6 июн. 2022 г.
- CVE-2023-2905932Наблюдать
3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023.
ВысокаяCVSS 7,8Эксплойта нетEPSS 4 %3cx · 3cx30 мар. 2023 г.
- CVE-2019-1317631Наблюдать
An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %3cx · 3cx8 авг. 2019 г.
- CVE-2022-4848231Наблюдать
3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electr
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %3cx · 3cx2 мая 2023 г.
- CVE-2022-4848331Наблюдать
3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/dow
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %3cx · 3cx2 мая 2023 г.
- CVE-2008-689531Наблюдать
3CX Phone System 6.0.806.0 allows remote attackers to cause a denial of service (unstable service or crash) via unspecified vectors, as demo
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %3cx · phone system3 авг. 2009 г.
- CVE-2023-2736231Наблюдать
3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %3cx · 3cx2 мая 2024 г.
- CVE-2019-1493531Наблюдать
3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %3cx · 3cx11 авг. 2019 г.
- CVE-2017-1535928Наблюдать
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/a
СредняяCVSS 6,5Proof of conceptEPSS 6 %3cx · 3cx18 окт. 2017 г.
- CVE-2018-765427Наблюдать
On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access to files on the serve
СредняяCVSS 6,5Эксплойта нетEPSS 2 %3cx · 3cx3 мар. 2018 г.
- CVE-2021-4549126Наблюдать
3CX System through 2022-03-17 stores cleartext passwords in a database.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %3cx · 3cx27 мар. 2022 г.
- CVE-2019-991324Наблюдать
The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %3cx · live chat21 мар. 2019 г.
- CVE-2018-986424Наблюдать
The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %3cx · live chat9 апр. 2018 г.
- CVE-2017-218724Наблюдать
Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arbitrary web script or
СредняяCVSS 6,1Эксплойта нетEPSS 1 %3cx · live chat9 июн. 2017 г.
- CVE-2019-1495024Наблюдать
The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
СредняяCVSS 6,1Proof of conceptEPSS 1 %3cx · live chat12 авг. 2019 г.
- CVE-2018-1110524Наблюдать
There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "emai
СредняяCVSS 6,1Эксплойта нетEPSS 1 %3cx · live chat15 мая 2018 г.
- CVE-2018-1846024Наблюдать
XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivech
СредняяCVSS 6,1Эксплойта нетEPSS 1 %3cx · live chat18 окт. 2018 г.