3CX kayıtları
3cx üreticisine ait 34 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-295 Improper Certificate Validation1
- CWE-427 Uncontrolled Search Path Element1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
34 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2022-28005İstismar yok | An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL.3cx · 3cx · CWE-522 | Kritik9,8 | — | %6,7 | 6 May 2022 |
41Planlayın | CVE-2018-12426İstismar yok | The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side va3cx · live chat · CWE-434 | Kritik9,8 | — | %5,1 | 2 Tem 2018 |
40Planlayın | CVE-2019-11185İstismar yok | The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability.3cx · live chat · CWE-434 | Kritik9,8 | — | %4,3 | 3 Haz 2019 |
40Planlayın | CVE-2023-49954Kavram kanıtı | The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address3cx · 3cx · CWE-89 | Kritik9,8 | — | %2,2 | 25 Ara 2023 |
40Planlayın | CVE-2019-12498İstismar yok | The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check pr3cx · live chat · CWE-862 | Kritik9,8 | — | %2,0 | 20 Mar 2020 |
36İzleyin | CVE-2019-9972İstismar yok | PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands 3cx · phone system firmware · CWE-77 | Yüksek8,8 | — | %1,7 | 7 Haz 2022 |
36İzleyin | CVE-2019-9971İstismar yok | PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo wi3cx · phone system firmware · CWE-269 | Yüksek8,8 | — | %1,7 | 7 Haz 2022 |
36İzleyin | CVE-2021-45490İstismar yok | The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate 3cx · 3cx · CWE-295 | Kritik9,1 | — | %1,1 | 27 Mar 2022 |
33İzleyin | CVE-2022-27438Kavram kanıtı | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affectcaphyon · advanced installer · CWE-494 | Yüksek8,1 | — | %2,0 | 6 Haz 2022 |
32İzleyin | CVE-2023-29059İstismar yok | 3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023.3cx · 3cx | Yüksek7,8 | — | %4,4 | 30 Mar 2023 |
31İzleyin | CVE-2019-13176İstismar yok | An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2.3cx · 3cx · CWE-611 | Yüksek7,5 | — | %2,5 | 8 Ağu 2019 |
31İzleyin | CVE-2022-48482İstismar yok | 3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electr3cx · 3cx · CWE-22 | Yüksek7,5 | — | %1,8 | 2 May 2023 |
31İzleyin | CVE-2022-48483İstismar yok | 3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/dow3cx · 3cx · CWE-22 | Yüksek7,5 | — | %1,7 | 2 May 2023 |
31İzleyin | CVE-2008-6895İstismar yok | 3CX Phone System 6.0.806.0 allows remote attackers to cause a denial of service (unstable service or crash) via unspecified vectors, as demo3cx · phone system | Yüksek7,8 | — | %1,2 | 3 Ağu 2009 |
31İzleyin | CVE-2023-27362İstismar yok | 3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability3cx · 3cx · CWE-427 | Yüksek7,8 | — | %0,4 | 2 May 2024 |
31İzleyin | CVE-2019-14935İstismar yok | 3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full 3cx · 3cx · CWE-732 | Yüksek7,8 | — | %0,4 | 11 Ağu 2019 |
28İzleyin | CVE-2017-15359Kavram kanıtı | In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/a3cx · 3cx · CWE-22 | Orta6,5 | — | %6,2 | 18 Eki 2017 |
27İzleyin | CVE-2018-7654İstismar yok | On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access to files on the serve3cx · 3cx · CWE-22 | Orta6,5 | — | %2,4 | 3 Mar 2018 |
26İzleyin | CVE-2021-45491İstismar yok | 3CX System through 2022-03-17 stores cleartext passwords in a database.3cx · 3cx · CWE-312 | Orta6,5 | — | %0,8 | 27 Mar 2022 |
24İzleyin | CVE-2019-9913İstismar yok | The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.3cx · live chat · CWE-79 | Orta6,1 | — | %1,4 | 21 Mar 2019 |
24İzleyin | CVE-2018-9864İstismar yok | The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.3cx · live chat · CWE-79 | Orta6,1 | — | %1,3 | 9 Nis 2018 |
24İzleyin | CVE-2017-2187İstismar yok | Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arbitrary web script or3cx · live chat · CWE-79 | Orta6,1 | — | %1,3 | 9 Haz 2017 |
24İzleyin | CVE-2019-14950Kavram kanıtı | The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.3cx · live chat · CWE-79 | Orta6,1 | — | %1,2 | 12 Ağu 2019 |
24İzleyin | CVE-2018-11105İstismar yok | There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "emai3cx · live chat · CWE-79 | Orta6,1 | — | %1,1 | 15 May 2018 |
24İzleyin | CVE-2018-18460İstismar yok | XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivech3cx · live chat · CWE-79 | Orta6,1 | — | %1,0 | 18 Eki 2018 |
- CVE-2022-2800541Planlayın
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL.
KritikCVSS 9,8İstismar yokEPSS %73cx · 3cx6 May 2022
- CVE-2018-1242641Planlayın
The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side va
KritikCVSS 9,8İstismar yokEPSS %53cx · live chat2 Tem 2018
- CVE-2019-1118540Planlayın
The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability.
KritikCVSS 9,8İstismar yokEPSS %43cx · live chat3 Haz 2019
- CVE-2023-4995440Planlayın
The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address
KritikCVSS 9,8Kavram kanıtıEPSS %23cx · 3cx25 Ara 2023
- CVE-2019-1249840Planlayın
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check pr
KritikCVSS 9,8İstismar yokEPSS %23cx · live chat20 Mar 2020
- CVE-2019-997236İzleyin
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands
YüksekCVSS 8,8İstismar yokEPSS %23cx · phone system firmware7 Haz 2022
- CVE-2019-997136İzleyin
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo wi
YüksekCVSS 8,8İstismar yokEPSS %23cx · phone system firmware7 Haz 2022
- CVE-2021-4549036İzleyin
The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate
KritikCVSS 9,1İstismar yokEPSS %13cx · 3cx27 Mar 2022
- CVE-2022-2743833İzleyin
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affect
YüksekCVSS 8,1Kavram kanıtıEPSS %2caphyon · advanced installer6 Haz 2022
- CVE-2023-2905932İzleyin
3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023.
YüksekCVSS 7,8İstismar yokEPSS %43cx · 3cx30 Mar 2023
- CVE-2019-1317631İzleyin
An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2.
YüksekCVSS 7,5İstismar yokEPSS %23cx · 3cx8 Ağu 2019
- CVE-2022-4848231İzleyin
3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electr
YüksekCVSS 7,5İstismar yokEPSS %23cx · 3cx2 May 2023
- CVE-2022-4848331İzleyin
3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/dow
YüksekCVSS 7,5İstismar yokEPSS %23cx · 3cx2 May 2023
- CVE-2008-689531İzleyin
3CX Phone System 6.0.806.0 allows remote attackers to cause a denial of service (unstable service or crash) via unspecified vectors, as demo
YüksekCVSS 7,8İstismar yokEPSS %13cx · phone system3 Ağu 2009
- CVE-2023-2736231İzleyin
3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %03cx · 3cx2 May 2024
- CVE-2019-1493531İzleyin
3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full
YüksekCVSS 7,8İstismar yokEPSS %03cx · 3cx11 Ağu 2019
- CVE-2017-1535928İzleyin
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/a
OrtaCVSS 6,5Kavram kanıtıEPSS %63cx · 3cx18 Eki 2017
- CVE-2018-765427İzleyin
On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access to files on the serve
OrtaCVSS 6,5İstismar yokEPSS %23cx · 3cx3 Mar 2018
- CVE-2021-4549126İzleyin
3CX System through 2022-03-17 stores cleartext passwords in a database.
OrtaCVSS 6,5İstismar yokEPSS %13cx · 3cx27 Mar 2022
- CVE-2019-991324İzleyin
The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.
OrtaCVSS 6,1İstismar yokEPSS %13cx · live chat21 Mar 2019
- CVE-2018-986424İzleyin
The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.
OrtaCVSS 6,1İstismar yokEPSS %13cx · live chat9 Nis 2018
- CVE-2017-218724İzleyin
Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arbitrary web script or
OrtaCVSS 6,1İstismar yokEPSS %13cx · live chat9 Haz 2017
- CVE-2019-1495024İzleyin
The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
OrtaCVSS 6,1Kavram kanıtıEPSS %13cx · live chat12 Ağu 2019
- CVE-2018-1110524İzleyin
There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "emai
OrtaCVSS 6,1İstismar yokEPSS %13cx · live chat15 May 2018
- CVE-2018-1846024İzleyin
XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivech
OrtaCVSS 6,1İstismar yokEPSS %13cx · live chat18 Eki 2018