Metrics
Affected Vendors & Products
Tue, 23 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sangoma
Sangoma freepbx |
|
| CPEs | cpe:2.3:a:sangoma:freepbx:17.0.19.17:*:*:*:*:*:*:* | |
| Vendors & Products |
Sangoma
Sangoma freepbx |
Tue, 14 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Thu, 09 Jan 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 |
Thu, 09 Jan 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A serious vulnerability was discovered in FreePBX 17.0.19.17. FreePBX does not verify the type of uploaded files and does not restrict user access paths, allowing attackers to remotely control the FreePBX server by uploading malicious files with malicious content and accessing the default directory where the files are uploaded. This will result in particularly serious consequences. | A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what high-privilege administrators are intentionally allowed to do. |
Thu, 09 Jan 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what high-privilege administrators are intentionally allowed to do. | A serious vulnerability was discovered in FreePBX 17.0.19.17. FreePBX does not verify the type of uploaded files and does not restrict user access paths, allowing attackers to remotely control the FreePBX server by uploading malicious files with malicious content and accessing the default directory where the files are uploaded. This will result in particularly serious consequences. |
Wed, 08 Jan 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A serious vulnerability was discovered in FreePBX 17.0.19.17. FreePBX does not verify the type of uploaded files and does not restrict user access paths, allowing attackers to remotely control the FreePBX server by uploading malicious files with malicious content and accessing the default directory where the files are uploaded. This will result in particularly serious consequences. | A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what high-privilege administrators are intentionally allowed to do. |
Wed, 08 Jan 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 03 Dec 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated arbitrary file upload vulnerability in the component /module_admin/upload.php of freepbx v17.0.19.17 allows attackers to execute arbitrary code via uploading a crafted file. | A serious vulnerability was discovered in FreePBX 17.0.19.17. FreePBX does not verify the type of uploaded files and does not restrict user access paths, allowing attackers to remotely control the FreePBX server by uploading malicious files with malicious content and accessing the default directory where the files are uploaded. This will result in particularly serious consequences. |
Tue, 03 Dec 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 03 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Coalescent Systems
Coalescent Systems freepbx |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:coalescent_systems:freepbx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Coalescent Systems
Coalescent Systems freepbx |
|
| Metrics |
cvssV3_1
|
Mon, 02 Dec 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated arbitrary file upload vulnerability in the component /module_admin/upload.php of freepbx v17.0.19.17 allows attackers to execute arbitrary code via uploading a crafted file. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-12-02T00:00:00
Updated: 2025-01-14T16:41:16.578Z
Reserved: 2024-11-20T00:00:00
Link: CVE-2024-53564
Updated: 2024-12-03T15:06:38.663Z
Status : Analyzed
Published: 2024-12-02T18:15:11.353
Modified: 2025-09-23T13:00:30.710
Link: CVE-2024-53564
No data.