漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module
Vulnerability Description
FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key and appends it to /home/asterisk/.ssh/authorized_keys for the asterisk system user without reliably enforcing backup-only command and source restrictions. The key grants persistent shell access that can execute arbitrary commands, access FreePBX and call data, modify system files, and disrupt services. This issue is fixed in version 17.0.11.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
特权管理不恰当
Vulnerability Title
FreePBX 权限许可和访问控制问题漏洞
Vulnerability Description
FreePBX是FreePBX团队开源的一款基于Web的电话交换系统。 FreePBX 17.0.5.34版本至17.0.11之前版本存在权限许可和访问控制问题漏洞,该漏洞源于Backup.class.php中的publicKeySave AJAX端点未可靠执行备份专用命令和来源限制,经过身份验证的管理员可将SSH公钥添加至authorized_keys文件,从而获取持久shell访问权限,执行任意命令、访问FreePBX和通话数据、修改系统文件以及中断服务。
CVSS Information
N/A
Vulnerability Type
N/A