Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the langChoice parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.633
EPSS Ranking 98.3%