Authenticated Arbitrary SSH Key Injection via Backup Module

Summary

A vulnerability exists in the FreePBX backup Module that allows authenticated attackers to upload unrestricted SSH keys that do much more than execute limited, relevant backup-related commands.

Authentication with a known username is required and this user typically requires administrator-level access to make use of backup functionality.

Common Vulnerabilities and Exposures (CVE)

Requested

GitHub Security Advisory (GHSA)

GHSA-24w6-hpg3-rwfg

Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)

G - Green

Link to Published GHSA with More Details

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.