An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIgniterealtime Openfire
APPIgniterealtime4.5.0< 4.5.0Pascom Cloud Phone System
APPPascom≤ 7.19
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References
Related vulnerabilities
CVE-2024-25421CRITICAL9.8PL ✓same product
Privilege escalation w Ignite Realtime Openfire przez komponent ROOM_CACHE
CVE-2021-45966CRITICAL9.8PL ✓same product
Command Injection w Pascom Cloud Phone System — zdalne wykonanie kodu
CVE-2019-18394CRITICAL9.8PL ✓same product
SSRF w Ignite Realtime Openfire — dowolne żądania HTTP GET
CVE-2023-32315HIGH8.6⚠ KEVsame product
Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a...
CVE-2024-25420HIGH7.2same product
An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admi...