An issue was discovered in Pascom Cloud Phone System...
Critical severity
Unreviewed
Published
Mar 19, 2022
to the GitHub Advisory Database
•
Updated Jan 12, 2024
Description
Published by the National Vulnerability Database
Mar 18, 2022
Published to the GitHub Advisory Database
Mar 19, 2022
Last updated
Jan 12, 2024
An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.
References