CVE-2025-57819
- EPSS 59.71%
- Veröffentlicht 28.08.2025 16:45:18
- Zuletzt bearbeitet 12.09.2025 13:59:26
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database ma...
CVE-2024-53564
- EPSS 0.13%
- Veröffentlicht 02.12.2024 18:15:11
- Zuletzt bearbeitet 23.09.2025 13:00:30
A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond...
CVE-2023-43336
- EPSS 0.08%
- Veröffentlicht 02.11.2023 12:15:09
- Zuletzt bearbeitet 21.11.2024 08:24:00
Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing extension=self to extension=101.
CVE-2019-25090
- EPSS 0.09%
- Veröffentlicht 27.12.2022 13:15:10
- Zuletzt bearbeitet 21.11.2024 04:39:54
A vulnerability was found in FreePBX arimanager up to 13.0.5.3 and classified as problematic. Affected by this issue is some unknown functionality of the component Views Handler. The manipulation of the argument dataurl leads to cross site scripting....
CVE-2020-36630
- EPSS 0.06%
- Veröffentlicht 25.12.2022 20:15:25
- Zuletzt bearbeitet 21.11.2024 05:29:56
A vulnerability was found in FreePBX cdr 14.0. It has been classified as critical. This affects the function ajaxHandler of the file ucp/Cdr.class.php. The manipulation of the argument limit/offset leads to sql injection. Upgrading to version 14.0.5....
CVE-2019-19852
- EPSS 0.31%
- Veröffentlicht 16.03.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:32
An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report screen in the cel module at the admin/config.php?display=cel URI via date fields. This affects cel through 13.0.26.9, 14.x through...
CVE-2019-19615
- EPSS 0.31%
- Veröffentlicht 16.03.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:03
Multiple XSS vulnerabilities exist in the Backup & Restore module \ v14.0.10.2 through v14.0.10.7 for FreePBX, as shown at /admin/config.php?display=backup on the FreePBX Administrator web site. An attacker can modify the id parameter of the backup c...
CVE-2019-19538
- EPSS 1.53%
- Veröffentlicht 16.03.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:34:55
In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command Execution vulnerability that results in Privilege Escalation.
CVE-2019-19851
- EPSS 0.29%
- Veröffentlicht 16.03.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:31
An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Superfecta module at the admin/config.php?display=superfecta URI. This affects Superfecta through 13.0.4.7, 14.x through 14.0.24, and...
CVE-2019-19552
- EPSS 0.41%
- Veröffentlicht 06.12.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:57
In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the user management screen of the Administrator web site, i.e., the/admin/config.php?display=userman URI. An attacker with sufficient privileges can edit the Display Name of a us...