Authenticated API generatedocs Host Command Injection

Summary

Authenticated users who are authorized to access the GraphQL api module interface of FreePBX are able to execute arbitrary shell commands.

Authenticated access to the api module is required.

Common Vulnerabilities and Exposures (CVE)

Requested

GitHub Security Advisory (GHSA)

GHSA-79rg-3xp6-rqq6

Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)

G - Green

Link to Published GHSA with More Details

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.