twilio / OpenVBX

OpenVBX is a web-based open source phone system for business.
http://openvbx.org
Other
700 stars 341 forks source link

Use of an outdated SWFUpload vulnerable to XSS #436

Open yassineaboukir opened 5 years ago

yassineaboukir commented 5 years ago

Hi,

OpenVBX is using an outdated version of SWFUpload that is vulnerable to Flash-based Cross-Site Scripting vulnerability (CVE-2012-3414).

It is highly advised upgrading to the latest version to mitigate the security issue.

Regards.