peter bassill · operator
$ cve CVE-2014-5335 JSON

CVE-2014-5335 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 1.2% (pctl 68)

Patch early

A public exploit exists.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in innovaphone PBX 10.00 sr11 and earlier allow remote attackers to hijack the authentication of administrators for requests that modify configurations or user accounts, as demonstrated by (1) changing the administrator password via a crafted request to CMD0/mod_cmd.xml or (2) adding a new SIP user via a crafted request to PBX0/ADMIN/mod_cmd_login.xml.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS1.22% — more likely to be exploited than 68% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2014-08-25
Last modified2026-06-17

Affected (1)

VendorProduct
innovaphoneinnovaphone pbx

Public exploits

SourceTitleDate
exploit-dbInnovaphone PBX Admin-GUI - Cross-Site Request Forgery2014-08-25

References

→ the Explorer  ·  watch your stack  ·  NVD