CVE-2019-16986: Fusionpbx

Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.

In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname and allows a download of it. (resources\secure_download.php is also affected.)

Affected products

  • Fusionpbx Fusionpbx: up to and including 4.5.7

Published 2019-10-21. Last modified 2026-06-17.