CVE-2025-59056

FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Administrator Control Panel web interface can cause the uninstall function to be triggered for certain modules. This function drops the module's database tables, which is where most modules store their configuration. This vulnerability is fixed in 15.0.38, 16.0.41, and 17.0.21.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*
cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*
cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*

History

17 Oct 2025, 14:36

Type Values Removed Values Added
CPE cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*
References () https://github.com/FreePBX/framework/blame/release/17.0/amp_conf/htdocs/admin/ajax.php#L18 - () https://github.com/FreePBX/framework/blame/release/17.0/amp_conf/htdocs/admin/ajax.php#L18 - Product
References () https://github.com/FreePBX/security-reporting/security/advisories/GHSA-frc2-jhgg-rwpr - () https://github.com/FreePBX/security-reporting/security/advisories/GHSA-frc2-jhgg-rwpr - Third Party Advisory, Mitigation
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Sangoma
Sangoma freepbx

15 Sep 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-15 21:15

Updated : 2025-10-17 14:36


NVD link : CVE-2025-59056

Mitre link : CVE-2025-59056

CVE.ORG link : CVE-2025-59056


JSON object : View

Products Affected

sangoma

  • freepbx
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')