A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what high-privilege administrators are intentionally allowed to do.
References
Link | Resource |
---|---|
https://gist.github.com/hyp164D1/490732de230edf97423f6d95b0d2f903 | Third Party Advisory |
https://gist.github.com/hyp164D1/d419bdf3e7e352088a21631d0f452a8c | Third Party Advisory |
Configurations
History
23 Sep 2025, 13:00
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/hyp164D1/490732de230edf97423f6d95b0d2f903 - Third Party Advisory | |
References | () https://gist.github.com/hyp164D1/d419bdf3e7e352088a21631d0f452a8c - Third Party Advisory | |
CPE | cpe:2.3:a:sangoma:freepbx:17.0.19.17:*:*:*:*:*:*:* | |
First Time |
Sangoma
Sangoma freepbx |
09 Jan 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
CWE |
09 Jan 2025, 01:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what high-privilege administrators are intentionally allowed to do. |
09 Jan 2025, 00:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) A serious vulnerability was discovered in FreePBX 17.0.19.17. FreePBX does not verify the type of uploaded files and does not restrict user access paths, allowing attackers to remotely control the FreePBX server by uploading malicious files with malicious content and accessing the default directory where the files are uploaded. This will result in particularly serious consequences. |
08 Jan 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 2.2 |
CWE | CWE-434 | |
Summary | (en) A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what high-privilege administrators are intentionally allowed to do. |
Information
Published : 2024-12-02 18:15
Updated : 2025-09-23 13:00
NVD link : CVE-2024-53564
Mitre link : CVE-2024-53564
CVE.ORG link : CVE-2024-53564
JSON object : View
Products Affected
sangoma
- freepbx
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type