CVE-2025-67722
- EPSS 0.01%
- Veröffentlicht 16.12.2025 00:14:18
- Zuletzt bearbeitet 16.12.2025 14:10:11
FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startup script `amp...
CVE-2024-58294
- EPSS 0.65%
- Veröffentlicht 11.12.2025 21:36:11
- Zuletzt bearbeitet 15.12.2025 17:10:56
FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POS...
CVE-2025-59429
- EPSS 0.19%
- Veröffentlicht 14.10.2025 19:26:02
- Zuletzt bearbeitet 16.10.2025 15:29:11
FreePBX is an open source GUI for managing Asterisk. In versions prior to 16.0.68.39 for FreePBX 16 and versions prior to 17.0.18.38 for FreePBX 17, a reflected cross-site scripting vulnerability is present on the Asterisk HTTP Status page. The Aster...
CVE-2018-15891
- EPSS 0.35%
- Veröffentlicht 20.06.2019 17:15:09
- Zuletzt bearbeitet 21.11.2024 03:51:39
An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4. By crafting a request for adding Asterisk modules, an attacker is able to store JavaScript commands in a module name.
- EPSS 57.42%
- Veröffentlicht 07.10.2014 14:55:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth cookie, related to the PHP uns...
CVE-2014-1903
- EPSS 83.71%
- Veröffentlicht 18.02.2014 11:55:16
- Zuletzt bearbeitet 11.04.2025 00:51:21
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote attackers to execut...
CVE-2009-4458
- EPSS 2.15%
- Veröffentlicht 30.12.2009 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) tech parameter to admin/admin/config.php during a trunks display...
CVE-2009-1801
- EPSS 0.48%
- Veröffentlicht 28.05.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote attackers to inject arbitrary web script or HTML via the (1) display parameter to reports.php, the (2) order an...
CVE-2009-1802
- EPSS 0.14%
- Veröffentlicht 28.05.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site request forgery (CSRF) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote attackers to hijack the authentication of admins for requests that create a new admin account or have un...
- EPSS 0.32%
- Veröffentlicht 28.05.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, generates different error messages for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.