Authenticated Command Injection in FreePBX UCP Interface

Summary

Users authenticated via User Control Panel (UCP) are able to execute arbitrary commands on the PBX as the webserver user (typically asterisk) using specially crafted HTTP strings.

Authenticated access to UCP is required. Note that this is often more common for less-privileged users to have UCP access vs. the Administrator Control Panel (ACP) access (which is usually FreePBX higher-level administrator accounts only).

Common Vulnerabilities and Exposures (CVE)

Requested

GitHub Security Advisory (GHSA)

GHSA-4jjr-8g5r-wv66

Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)

A - Amber

Link to Published GHSA with More Details

Highlights

Provider Urgency accordingly set to Amber because of longevity and increased exposure of UCP vs ACP.

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.