PT-2026-99961 · Freepbx · Freepbx
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FreePBX versions prior to 16.0.40
FreePBX versions prior to 17.0.7
Description
A remote code execution issue exists in the superfecta module due to the unsafe inclusion of arbitrary PHP files. Authenticated attackers with a known username can execute arbitrary PHP code on the server with web server user privileges. The flaw is located in the
options and save options cases of the superfecta module's AJAX handler, where PHP files from the sources/ directory are dynamically included based on user input. This can be exploited when combined with arbitrary directory creation and file uploads that reveal full paths.Recommendations
Update to version 16.0.40 or later.
Update to version 17.0.7 or later.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freepbx