PT-2026-99957 · Freepbx · Freepbx
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FreePBX versions prior to 16.0.4
FreePBX versions prior to 17.0.6
Description
The Music on Hold (MoH) module allows authenticated attackers with administrator privileges to execute arbitrary system commands with the permissions of the Asterisk service. The issue occurs because the module accepts a POST parameter for a custom Asterisk application and stores it in the database without sanitization. This data is subsequently written to the
musiconhold additional.conf configuration file without validation. When Asterisk reads this file and executes the specified application, it triggers the execution of the injected commands.Recommendations
Update to version 16.0.4 or newer.
Update to version 17.0.6 or newer.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freepbx