A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what high-privilege administrators are intentionally allowed to do.
References
| Link | Resource |
|---|---|
| https://gist.github.com/hyp164D1/490732de230edf97423f6d95b0d2f903 | Third Party Advisory |
| https://gist.github.com/hyp164D1/d419bdf3e7e352088a21631d0f452a8c | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-12-02 18:15
Updated : 2025-09-23 13:00
NVD link : CVE-2024-53564
Mitre link : CVE-2024-53564
CVE.ORG link : CVE-2024-53564
JSON object : View
Products Affected
sangoma
- freepbx
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
