Summary
The FreePBX Text-To-Speech (TTS) module destination name can be manipulated into a raw shell command, executing on the host as the asterisk user.
Authentication with an existing FreePBX administrator account is required.
Common Vulnerabilities and Exposures (CVE)
Requested
GitHub Security Advisory (GHSA)
GHSA-hg3v-m857-mvw9
Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)
G - Green
Link to Published GHSA with More Details
Highlights
![]()