Reflected Cross-Site Scripting Vulnerability in FreePBX by FreePBX
CVE-2025-59429
What is CVE-2025-59429?
FreePBX, an open-source GUI for managing Asterisk, has a reflected cross-site scripting vulnerability present on the Asterisk HTTP Status page. This issue affects versions prior to 16.0.68.39 for FreePBX 16 and versions prior to 17.0.18.38 for FreePBX 17. Attackers can exploit this vulnerability, available by default on version 16 at any bound IP address on port 8088, and in a more restricted manner on version 17, to obtain session cookies from logged-in users. This facilitates session hijacking of administrative users, allowing attackers to gain unauthorized control over the FreePBX admin interface. Such access can lead to unauthorized data exposure, system configuration modifications, the creation of backdoor accounts, and potential service disruptions. Patches have been released for affected versions, highlighting the importance of timely updates for security.
Affected Version(s)
security-reporting < 16.0.68.39 < 16.0.68.39
security-reporting >= 17.0.0, < 17.0.18.38 < 17.0.0, 17.0.18.38