FreePBX Endpoint Manager是FreePBX开源的一款集中管理IP电话终端配置模块。 FreePBX Endpoint Manager 16.0.92之前版本和17.0.6之前版本存在操作系统命令注入漏洞,该漏洞源于用户输入清理不足,可能导致经过身份验证的攻击者以asterisk用户身份执行OS命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-59429 | FreePBX core module vulnerable to reflected cross-site scripting via Asterisk HTTP Status | |
| CVE-2025-61678 | FreePBX Endpoint Manager vulnerable to authenticated arbitrary file upload via fwbrand par | |
| CVE-2025-61675 | FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configurati |
No comments yet