THE article discusses critical cybersecurity vulnerabilities in FreePBX, specifically two high-severity flaws each with a CVSS score of 9.3. One vulnerability allows unauthenticated remote code execution via the UCP module, while the other involves a SQL injection that can grant administrator takeover. Currently, there is no confirmed public exploit for these issues. The vulnerabilities affect FreePBX versions prior to 17.0.9 and 16.0.11, with recommended patches available. Immediate action is advised to update modules and secure systems against potential attacks, particularly for servers exposed to the internet.
FreePBX flaws allow remote code execution and admin takeover
CyberSIXT Evidence Panel
Primary Source
github.com
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
FreePBX flaws allow remote code execution and admin takeover
securityonline.info
-
FreePBX modules Superfecta and UCP hit by critical RCE bugs
securityonline.info