Описание
FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Product
- Third Party Advisory
- Exploit
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:sangoma:freepbx:16.0:*:*:*:*:*:*:*
EPSS
Процентиль: 73%
0.00762
Низкий
8.8 High
CVSS3
Дефекты
CWE-78
Связанные уязвимости
CVSS3: 8.8
github
7 дней назад
FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access.
EPSS
Процентиль: 73%
0.00762
Низкий
8.8 High
CVSS3
Дефекты
CWE-78