An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.
{ "cpes": [ "cpe:2.3:a:igniterealtime:openfire:*:*:*:*:*:*:*:*", "cpe:2.3:a:igniterealtime:openfire:4.5.0:-:*:*:*:*:*:*" ], "severity": "Critical" }