Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-53564


A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what high-privilege administrators are intentionally allowed to do.


Published

2024-12-02T18:15:11.353

Last Modified

2025-09-23T13:00:30.710

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 2.2 (LOW)

Weaknesses
  • Type: Secondary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sangoma freepbx 17.0.19.17 Yes

References