CVE-2019-11407: Fusionpbx

High severity, CVSS 7.2. EPSS: 1.5% chance of exploitation in the next 30 days.

app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to excessive debug information, which allows authenticated administrative attackers to obtain credentials and other sensitive information.

Affected products

Published 2019-06-17. Last modified 2026-06-17.