Summary
Users authenticated via User Control Panel (UCP) are able to execute arbitrary commands on the PBX as the webserver user (typically asterisk) using specially crafted HTTP strings.
Authenticated access to UCP is required. Note that this is often more common for less-privileged users to have UCP access vs. the Administrator Control Panel (ACP) access (which is usually FreePBX higher-level administrator accounts only).
Common Vulnerabilities and Exposures (CVE)
Requested
GitHub Security Advisory (GHSA)
GHSA-4jjr-8g5r-wv66
Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)
A - Amber
Link to Published GHSA with More Details
Highlights
Provider Urgency accordingly set to Amber because of longevity and increased exposure of UCP vs ACP.