PT-2026-71884 · Freepbx · Freepbx
CVE-2026-73663
·
Published
2026-08-13
·
Updated
2026-08-13
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreePBX versions 16.0.0 through 16.0.10
FreePBX versions prior to 17.0.4
Description
The missedcall module fails to properly escape or use bound parameters when inserting the inbound Caller ID name from SIP From headers into the missedcalllog. This occurs within the
agi-bin/missedcallnotify.php file. An unauthenticated caller can exploit this by sending crafted SIP headers when a monitored extension goes unanswered, allowing for SQL injection. This can lead to database corruption and the modification of administrator accounts to gain unauthorized remote access.Recommendations
Update to version 16.0.11.
Update to version 17.0.4.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freepbx