🟢 Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup

Summary

The FreePBX Framework module’s AUTHTYPE hidden option can be set during backup restoration, allowing a crafted backup to disable the authentication method during restoration.

Authentication with a known username that has sufficient access permissions and/or write access to backup files is required.

Common Vulnerabilities and Exposures (CVE)

Requested

GitHub Security Advisory (GHSA)

GHSA-f6hc-rqxg-ch86

Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)

G - Green

Link to Published GHSA with More Details

Highlights

:green_circle: