FreePBX 13 and 14 has SQL Injection in the DISA module via the hangup variable on the /admin/config.php?display=disa&view=form page.
2019-06-20T17:15:09.893
2024-11-21T03:51:39.693
Modified
CVSSv3.0: 4.3 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8
6.4