PT-2026-99962 · Freepbx · Freepbx
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreePBX versions prior to 17.0.9
Description
Authenticated users with access to the GraphQL api module interface can execute arbitrary shell commands. The issue occurs because the PBX API module documentation generator uses an authenticated
host parameter to construct a shell command without proper validation or escaping. Although the system validates the OAuth access token, the lack of sanitization for the host variable allows command execution with the privileges of the FreePBX web/PBX service user, typically asterisk.Recommendations
Update to version 17.0.9.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freepbx