Vulnerability Details CVE-2025-30005
Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any retrieved file in place of the expected report.
This issue affects CompletePBX: all versions up to and prior to 5.2.35
Exploit prediction scoring system (EPSS) score
EPSS Score 0.571
EPSS Ranking 98.0%
CVSS Severity
CVSS v3 Score 6.7
Products affected by CVE-2025-30005
-
cpe:2.3:a:xorcom:completepbx:*