CVE-2024-53564
02.12.2024, 18:15
A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what high-privilege administrators are intentionally allowed to do.Enginsight
Vendor | Product | Version |
---|---|---|
sangoma | freepbx | 17.0.19.17 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration