PT-2026-99958 · Freepbx · Freepbx
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FreePBX versions prior to 16.0.39
FreePBX versions prior to 17.0.7
Description
Authenticated users of the User Control Panel (UCP) can execute arbitrary commands on the PBX as the webserver user, typically
asterisk, by using specially crafted HTTP strings. The issue stems from insufficient sanitization of certain URL parameters within the UCP, which allows for the execution of binaries on the host server through command chaining.Recommendations
Update to version 16.0.39 or later.
Update to version 17.0.7 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freepbx