
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A directory traversal vulnerability was discovered in 3CX Phone Management System version 18, identified as CVE-2022-28005. The vulnerability allowed an unauthenticated attacker to abuse improperly secured access to arbitrary files on the server via the /Electron/download directory traversal functionality (Medium Blog).
The vulnerability existed in the ElectronController's Download method, accessible via /download/{platform}/{file} endpoint. The issue stemmed from improper handling of Path.Combine() calls, where Windows backslash character could be used to bypass directory restrictions. The vulnerability allowed access to files under C:\ProgramData\3CX\Instance1\Data and its subdirectories initially, but was later found to allow access to any system file through absolute path traversal (Medium Blog).
The vulnerability allowed unauthorized access to sensitive files including credentials, chat logs, call recordings, and full backups of the 3CX installation. Since the application ran with NT AUTHORITY\SYSTEM privileges, the impact was maximized as it potentially allowed access to any file on the system (Medium Blog).
The vulnerability was initially patched in 3CX Version 18, Update 2 Security Hotfix, Build 18.0.2.315 in February 2022. After the discovery of a bypass, a second patch was released in 3CX Version 18, Update 3 FINAL, Build 18.0.3.450. A final security hotfix was released in March 2022 to fully address the vulnerability (3CX Blog, 3CX Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”