Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Fernando Pompeo Amatte

#38579of 56,330
7.5Total CVSS
Vulnerabilities · 1
PT-2021-8989
7.5
2021-04-12
Unknown · Liberty Lispbx · CVE-2019-15059
**Name of the Vulnerable Software and Affected Versions** Liberty lisPBX versions 2.0 through 2.0-4 **Description** The issue allows remote retrieval of configuration backup files without requiring authentication or authorization. These files contain sensitive PBX information, including extension numbers, contacts, and passwords, which can be accessed through specific paths, such as `/backup/lispbx-CONF-YYYY-MM-DD.tar` or `/backup/lispbx-CDR-YYYY-MM-DD.tar`. **Recommendations** For Liberty lisPBX versions 2.0 through 2.0-4, restrict access to the `/backup` directory to prevent unauthorized retrieval of configuration backup files. Consider implementing proper authentication and authorization mechanisms for accessing these files.