Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-57819


FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.


Published

2025-08-28T17:15:36.790

Last Modified

2025-09-02T14:48:31.737

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-89
    CWE-288

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sangoma freepbx < 15.0.66 Yes
Application sangoma freepbx < 16.0.89 Yes
Application sangoma freepbx < 17.0.3 Yes

References