module

Xorcom CompletePBX Arbitrary File Read and Deletion via systemDataFileName

Disclosed
Mar 2, 2025

Description

This module exploits an authenticated path traversal vulnerability in
Xorcom CompletePBX `systemDataFileName` parameter in the `diagnostics` module, allowing authenticated attackers
to retrieve arbitrary files from the system.

Additionally, the exploitation of this vulnerability results in the **deletion** of the
requested file from the target system.

The vulnerability is identified as CVE-2025-30005.
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.