CVE-2020-21057: Fusionpbx

High severity, CVSS 8.1. EPSS: 1.5% chance of exploitation in the next 30 days.

Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php.

Affected products

Published 2021-05-20. Last modified 2026-06-17.