CVE-2025-30005 Details
Description
Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any retrieved file in place of the expected report. This issue affects CompletePBX: all versions up to and prior to 5.2.35
A path traversal vulnerability has been identified in Xorcom CompletePBX, affecting all versions prior to 5.2.35. This vulnerability resides within the Diagnostics reporting module, where it allows unauthorized access to arbitrary files. Additionally, the issue enables the deletion of any retrieved file, replacing it with the expected report.
Users are advised to update to CompletePBX version 5.2.36.1 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vulncheck.com/advisories/completepbx-path-traversal-file-deletion | [email protected] | Third Party Advisory |
| https://www.xorcom.com/new-completepbx-release-5-2-36-1/ | [email protected] | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| xorcom completepbx | < 5.2.36.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 27, 2025 | CVE Modified | [email protected] |
| Sep 23, 2025 | Initial Analysis | [email protected] |
| Mar 31, 2025 | New CVE Received | [email protected] |