Reflected Cross-Site Scripting Vulnerability in FreePBX by FreePBX
CVE-2025-59429
What is CVE-2025-59429?
FreePBX, an open-source GUI for managing Asterisk, has a reflected cross-site scripting vulnerability present on the Asterisk HTTP Status page. This issue affects versions prior to 16.0.68.39 for FreePBX 16 and versions prior to 17.0.18.38 for FreePBX 17. Attackers can exploit this vulnerability, available by default on version 16 at any bound IP address on port 8088, and in a more restricted manner on version 17, to obtain session cookies from logged-in users. This facilitates session hijacking of administrative users, allowing attackers to gain unauthorized control over the FreePBX admin interface. Such access can lead to unauthorized data exposure, system configuration modifications, the creation of backdoor accounts, and potential service disruptions. Patches have been released for affected versions, highlighting the importance of timely updates for security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
security-reporting < 16.0.68.39 < 16.0.68.39
security-reporting >= 17.0.0, < 17.0.18.38 < 17.0.0, 17.0.18.38
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
