cve/2018/CVE-2018-7654.md
2024-06-18 02:51:15 +02:00

643 B

CVE-2018-7654

Description

On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access to files on the server via path traversal.

POC

Reference

Github

No PoCs found on GitHub currently.