- Description
- Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any retrieved file in place of the expected report. This issue affects CompletePBX: all versions up to and prior to 5.2.35
- Source
- disclosure@vulncheck.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 6.7
- Impact score
- 5.5
- Exploitability score
- 1.2
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
- Severity
- MEDIUM
- disclosure@vulncheck.com
- CWE-22
- Hype score
- Not currently trending
CVE-2025-30005 Path Traversal in Xorcom CompletePBX Diagnostics Reporting Module Before 5.2.35 https://t.co/T2ba3IoWXQ
@VulmonFeeds
1 Apr 2025
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 4 CVEs in Xorcom CompletePBX <= 5.2.35 (now fixed) CVE-2025-2292: https://t.co/kAG2scTBk7 CVE-2025-30004: https://t.co/PpFTjREfBj CVE-2025-30005: https://t.co/2EKxryobh8 CVE-2025-30006: https://t.co/L6xvCzCkEa Full details in June
@Chocapikk_
31 Mar 2025
1203 Impressions
5 Retweets
32 Likes
8 Bookmarks
0 Replies
0 Quotes
CVE-2025-30005 Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any ret… https://t.co/zPCfmYwr8Y
@CVEnew
31 Mar 2025
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes