漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Frogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution
Vulnerability Description
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pinsets, fm_show_context, fm_get_mcp_config, fm_backup_status, fm_whos_calling, fm_run_saved_query, and fm_diagnose_trunk, exposing AMI manager secrets, outbound dial PINs, full Asterisk dialplan context, root SSH connection commands, backup artifact paths, CDR history, arbitrary saved GraphQL query execution, and raw AMI endpoint dumps containing SIP fields such as password, md5_cred, and oauth_secret. This issue is fixed in version 1.6.3.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Vulnerability Type
授权机制缺失
Vulnerability Title
Michael White Frogman 授权问题漏洞
Vulnerability Description
Michael White Frogman是Michael White个人开发者的一款通过 MCP 和 HTTP API 实现无头 PBX 控制的软件。 Michael White Frogman 1.6.3之前版本存在授权问题漏洞,该漏洞源于授权问题(CWE-862),PERM_READ访问权限即可调用多个API端点,导致暴露AMI管理器密钥、出站拨号PIN、完整的Asterisk拨号计划环境、root SSH连接命令、备份工件路径、CDR历史记录、任意已保存的GraphQL查询执行以及包含密码、md5
CVSS Information
N/A
Vulnerability Type
N/A