CVE-2012-4870 | FreePBX 2.9 /recordings/index.php login cross site scripting (Unofficial Patch / EDB-18649)
A vulnerability classified as critical was found in FreePBX 2.9. This vulnerability affects unknown code of the file /recordings/index.php. The manipulation of the argument login with the input '>[XSS] leads to cross site scripting.
This vulnerability was named CVE-2012-4870. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.