📦 3cx

by 3cx

🔍 What is 3cx?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-49954

CRITICAL CVSS 9.8 Dec 25, 2023

This SQL injection vulnerability in 3CX CRM Integration allows attackers to execute arbitrary SQL commands by manipulating first name, search string, or email address fields. Attackers can potentially...

CVE-2022-28005

CRITICAL CVSS 9.8 May 6, 2022

This vulnerability in 3CX Phone System Management Console allows unauthenticated attackers to read arbitrary files via directory traversal, leading to credential disclosure. With stolen credentials, a...

CVE-2023-27362

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows local attackers to escalate privileges on 3CX installations by exploiting an insecure OpenSSL configuration file location. Attackers with initial low-privileged access can ex...

CVE-2022-48482

HIGH CVSS 7.5 May 2, 2023

CVE-2022-48482 is a directory traversal vulnerability in 3CX phone management software that allows unauthenticated remote attackers to read sensitive files including credentials, backups, call recordi...

CVE-2023-29059

HIGH CVSS 7.8 Mar 30, 2023

CVE-2023-29059 involves malicious code embedded in 3CX DesktopApp versions, enabling supply chain attacks. This allows attackers to execute arbitrary code on affected systems through DLL sideloading. ...