CVE-2025-30005
HIGH 8.3EPSS 1.8%
Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any retrieved file in place of the expected report.This issue affects CompletePBX: all versions up to and prior to 5.2.35
- CVSS v3.1
- 8.3 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L - CVSS v3.1
- 8.3 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L - EPSS
- 1.81% chance of exploitation in the next 30 days, 77th percentile
- Published
- 2025-03-31
- Updated
- 2025-12-27