๐Ÿ” CVE Alert

CVE-2024-53564

LOW 2.2
CVSS Score
2.2
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what high-privilege administrators are intentionally allowed to do.

CWE CWE-434
Vendor sangoma
Product freepbx
Published Dec 2, 2024
Last Updated Jan 14, 2025
Stay Ahead of the Next One

Get instant alerts for sangoma freepbx

Be the first to know when new low vulnerabilities affecting sangoma freepbx are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Sangoma / FreePBX
17.0.19.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gist.github.com: https://gist.github.com/hyp164D1/490732de230edf97423f6d95b0d2f903 gist.github.com: https://gist.github.com/hyp164D1/d419bdf3e7e352088a21631d0f452a8c