CVE-2012-4870 | FreePBX 2.9 /flash/mypage.php clid/clidname cross site scripting (Unofficial Patch / EDB-18649)
A vulnerability was found in FreePBX 2.9. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /flash/mypage.php. The manipulation of the argument clid/clidname leads to cross site scripting.
This vulnerability is known as CVE-2012-4870. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.