Reflected Cross-Site Scripting Vulnerability in FreePBX by FreePBX
CVE-2025-59429

8.5HIGH

Key Information:

Vendor

Freepbx

Vendor
CVE Published:
14 October 2025

What is CVE-2025-59429?

FreePBX, an open-source GUI for managing Asterisk, has a reflected cross-site scripting vulnerability present on the Asterisk HTTP Status page. This issue affects versions prior to 16.0.68.39 for FreePBX 16 and versions prior to 17.0.18.38 for FreePBX 17. Attackers can exploit this vulnerability, available by default on version 16 at any bound IP address on port 8088, and in a more restricted manner on version 17, to obtain session cookies from logged-in users. This facilitates session hijacking of administrative users, allowing attackers to gain unauthorized control over the FreePBX admin interface. Such access can lead to unauthorized data exposure, system configuration modifications, the creation of backdoor accounts, and potential service disruptions. Patches have been released for affected versions, highlighting the importance of timely updates for security.

Affected Version(s)

security-reporting < 16.0.68.39 < 16.0.68.39

security-reporting >= 17.0.0, < 17.0.18.38 < 17.0.0, 17.0.18.38

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59429 : Reflected Cross-Site Scripting Vulnerability in FreePBX by FreePBX