vendor:
FreePBX
by:
i-Hmx
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: FreePBX
Affected Version From: 13.0.35
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: freepbx
Platforms Tested:
Unauthenticated SQL Injection in FreePBX
The vulnerability exists due to insufficient sanitization of the 'display' parameter in the 'getAll' function in the 'DB.class.php' file and the 'getinfo' function in the 'modulefunctions.class.php' file. An attacker can exploit this vulnerability to execute arbitrary SQL commands in the database.
Mitigation:
Apply the latest security patches provided by the vendor.