CyberRota Analysis
AI-GeneratedThe FreePBX backup module prior to versions 16.0.72 and 17.0.7 is vulnerable to arbitrary code execution due to improper path sanitization, allowing authenticated users with sufficient permissions to upload malicious PHP files to the server's web root directory. This poses a significant risk as it can lead to full system compromise. Organizations using affected versions should prioritize patching to mitigate potential exploitation by attackers.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
FreePBX is an open source IP PBX. Prior to versions 16.0.72 and 17.0.7, a critical vulnerability exists in the FreePBX backup Module that allows authenticated attackers to execute arbitrary code on the server. Authentication with a known username that has sufficient access permissions and/or write access to backup files is required. This vulnerability is caused by improper path sanitization in the backup restore functionality, enabling attackers to upload malicious PHP files to the web root directory. This issue has been patched in versions 16.0.72 and 17.0.7.