Xorcom CompletePBX Path Traversal Vulnerability in Diagnostics Module Allowing Arbitrary File Access and Deletion

Vulnerability

A path traversal vulnerability has been identified in Xorcom CompletePBX, affecting all versions prior to 5.2.35. This vulnerability resides within the Diagnostics reporting module, where it allows unauthorized access to arbitrary files. Additionally, the issue enables the deletion of any retrieved file, replacing it with the expected report.

Impact

Exploitation of this vulnerability could lead to unauthorized file access and deletion of files on the server.

Remediation

Users are advised to update to CompletePBX version 5.2.36.1 or later, where this vulnerability has been patched.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
4.8
remediation
7.7
relevance
0.0
threat
1.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.