Sangoma

Freepbx

44 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 13.08.2026 21:32:02
  • Zuletzt bearbeitet 09.10.2026 19:29:45

FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the default namespace. An unauthenticated client can c...

  • EPSS 0.95%
  • Veröffentlicht 13.08.2026 21:29:14
  • Zuletzt bearbeitet 09.10.2026 19:31:28

FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bo...

  • EPSS 0.66%
  • Veröffentlicht 13.08.2026 21:27:14
  • Zuletzt bearbeitet 09.10.2026 19:32:16

FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed players in validateCustomConfiguration() in Music.class.php. An authenticated ad...

  • EPSS 0.34%
  • Veröffentlicht 13.08.2026 21:25:26
  • Zuletzt bearbeitet 09.10.2026 19:44:06

FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/admin/libraries/Builtin/Restore.p...

  • EPSS 0.2%
  • Veröffentlicht 29.05.2026 12:46:22
  • Zuletzt bearbeitet 21.07.2026 12:10:00

FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials during token issuance. Knowledge of a valid client_id is required. The validateClient() method in Clie...

  • EPSS 0.29%
  • Veröffentlicht 29.05.2026 12:44:26
  • Zuletzt bearbeitet 21.07.2026 12:10:00

FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST parameters. Authentication with a FreePBX Administration Control Panel account that has CDR section acces...

  • EPSS 0.27%
  • Veröffentlicht 29.05.2026 12:42:32
  • Zuletzt bearbeitet 21.07.2026 12:10:00

FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST['rawname'] parameter is concatenated into an includ...

Medienbericht
  • EPSS 0.43%
  • Veröffentlicht 29.05.2026 12:39:57
  • Zuletzt bearbeitet 21.07.2026 12:10:00

FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if these were not immediately changed by the Administr...

  • EPSS 8.03%
  • Veröffentlicht 05.03.2026 18:25:54
  • Zuletzt bearbeitet 06.03.2026 17:55:42

FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vulnerabilities exist in the recordings module. This issue has been patched in versions 16.0.20 and 17....

  • EPSS 0.25%
  • Veröffentlicht 05.03.2026 18:24:50
  • Zuletzt bearbeitet 06.03.2026 18:32:58

FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vulnerabilities. This issue has been patched in versions 16.0.10 and 17.0.5.