Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-58294


FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access.


Published

2025-12-11T22:15:50.423

Last Modified

2025-12-15T17:10:56.713

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sangoma freepbx 16.0 Yes

References