QID 730044

Date Published: 2021-04-27

QID 730044: FreePBX Incorrect Access Control Vulnerability (SEC-2019-001)

FreePBX is a web-based configuration tool for the open-source Asterisk PBX implemented in PHP.

FreePBX is vulnerable to Incorrect Access Control

Affected Versions:
FreePBX 13 prior to v13.0.197.14
FreePBX 14 prior to v14.0.13.12
FreePBX 15 prior to v15.0.16.27
QID Detection Logic:
This QID checks for the vulnerable version of FreePBX by sending get request to admin/config.php

Successful exploitation could compromise confidentiality, integrity and availability

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released advisories and updates to fix these vulnerabilities. Refer to the following link for details: Security Vulnerability Notice.

    CVEs related to QID 730044

    Software Advisories
    Advisory ID Software Component Link
    SEC-2019-001 URL Logo community.freepbx.org/t/freepbx-security-vulnerability-sec-2019-001/62772