- Description
- Xorcom CompletePBX is vulnerable to a reflected cross-site scripting (XSS) in the administrative control panel. This issue affects CompletePBX: all versions up to and prior to 5.2.35
- Source
- disclosure@vulncheck.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 6.1
- Impact score
- 2.7
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- disclosure@vulncheck.com
- CWE-79
- Hype score
- Not currently trending
🚨 4 CVEs in Xorcom CompletePBX <= 5.2.35 (now fixed) CVE-2025-2292: https://t.co/kAG2scTBk7 CVE-2025-30004: https://t.co/PpFTjREfBj CVE-2025-30005: https://t.co/2EKxryobh8 CVE-2025-30006: https://t.co/L6xvCzCkEa Full details in June
@Chocapikk_
31 Mar 2025
1203 Impressions
5 Retweets
32 Likes
8 Bookmarks
0 Replies
0 Quotes
CVE-2025-30006 Xorcom CompletePBX is vulnerable to a reflected cross-site scripting (XSS) in the administrative control panel. This issue affects CompletePBX: all versions up to… https://t.co/DlOQNC9Eww
@CVEnew
31 Mar 2025
300 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes