Unauthenticated Access Vulnerability in FreePBX by Sangoma Technologies
CVE-2025-57819
10CRITICAL
What is CVE-2025-57819?
FreePBX, an open-source web-based GUI, suffers from a vulnerability that permits unauthenticated users to gain access to the FreePBX Administrator interface. This is primarily due to insufficient sanitization of user-provided data. The flaw can lead to unauthorized database manipulation and may allow remote code execution, posing a significant risk to affected systems. Patches have been provided in versions 15.0.66, 16.0.89, and 17.0.3 to mitigate this vulnerability. Users are advised to upgrade to these versions to protect their systems.
Affected Version(s)
security-reporting < 15.0.66 < 15.0.66
security-reporting < 16.0.89 < 16.0.89
security-reporting < 17.0.3 < 17.0.3