🟢 Authenticated but Broken access control in the FreePBX framework GraphQL API

Summary

A GraphQL API user with read-only permissions could actually elevate their privileges enough to write some things, for example, an attacker might be able to add new administrator accounts with credentials of their choice.

Authentication with known API credentials is required.

Common Vulnerabilities and Exposures (CVE)

Requested

GitHub Security Advisory (GHSA)

GHSA-m8mc-g8fg-4765

Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)

G - Green

Link to Published GHSA with More Details

Highlights

:green_circle: