Michael White Frogman是Michael White个人开发者的一款通过 MCP 和 HTTP API 实现无头 PBX 控制的软件。 Michael White Frogman 1.6.2之前版本存在日志信息泄露漏洞,该漏洞源于fm_reset_password函数返回明文密码以及fm_add_extension函数返回明文密钥,可能导致任何具有PERM_READ权限的调用者通过访问fm_audit_search恢复存储的凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-46512 | 9.9 CRITICAL | Frogman: Dialplan template parameters interpolated into extensions_custom.conf without esc |
| CVE-2026-46513 | 7.4 HIGH | Frogman: API tokens stored in plaintext |
| CVE-2026-46515 | Frogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution |
No comments yet