### [CVE-2018-7654](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7654) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access to files on the server via path traversal. ### POC #### Reference - https://medium.com/stolabs/path-traversal-in-3cx-7421a8ffdb7a #### Github No PoCs found on GitHub currently.