Rapid7

module

Xorcom CompletePBX Authenticated File Disclosure via Backup Download

Disclosed
Mar 2, 2025
Created
Jul 22, 2025

Description

This module exploits an authenticated file disclosure vulnerability in CompletePBX
The issue resides in the backup download function, where user input is not properly validated,
allowing an attacker to access arbitrary files on the system as root.

The vulnerability is triggered by setting the `backup` parameter to a Base64-encoded
absolute file path, prefixed by a comma `,`. This results in the server exposing the
file contents directly.

Author

Valentin Lobstein

Platform

Linux,Unix

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use auxiliary/scanner/http/xorcom_completepbx_file_disclosure
msf auxiliary(xorcom_completepbx_file_disclosure) > show actions
...actions...
msf auxiliary(xorcom_completepbx_file_disclosure) > set ACTION < action-name >
msf auxiliary(xorcom_completepbx_file_disclosure) > show options
...show and set options...
msf auxiliary(xorcom_completepbx_file_disclosure) > run

Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.