🟠 Unauthenticated Missing Authorization in FreePBX UCP allows reset/overwrite of any user's dashboard templates

Summary

An unauthenticated missing-authorization (IDOR) vulnerability in the FreePBX UCP (User Control Panel) module allows any remote, unauthenticated attacker to reset or overwrite the dashboard/template configuration of any UCP user, and to overwrite shared administrator-defined templates.

Provider Urgency set to Amber. Please update now.

Common Vulnerabilities and Exposures (CVE)

Requested

GitHub Security Advisory (GHSA)

GHSA-rgq3-mgw4-rcfh

Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)

A - Amber

Link to Published GHSA with More Details

Highlights

:orange_circle: