PoC Index

CVE-2025-30005

HIGH 8.3EPSS 1.8%

Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any retrieved file in place of the expected report.This issue affects CompletePBX: all versions up to and prior to 5.2.35

CVSS v3.1
8.3 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CVSS v3.1
8.3 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
EPSS
1.81% chance of exploitation in the next 30 days, 77th percentile
Published
2025-03-31
Updated
2025-12-27

Metasploit modules (1)

References

Related