An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the sound_path parameter and fails to properly validate file paths before accessing the underlying filesystem. By supplying absolute paths, an authenticated attacker can retrieve files outside the intended directory scope.
| Vendor | Product | Versions |
|---|---|---|
| sangoma | switchvox smb edition | 8.3 (104997) |
Loading…
Article confirms local-only attack requirement and establishes severity as MEDIUM (estimated CVSS 4.3); added MITRE ATT&CK technique T1083 for file enumeration activity.
Initial creation