Authenticated SQL Injection Vulnerability in FreePBX Endpoint Module
CVE-2025-62173
8.6HIGH
What is CVE-2025-62173?
An authenticated SQL Injection vulnerability exists in the Endpoint Module of FreePBX. This flaw could allow attackers with valid credentials to execute arbitrary SQL commands via the module's REST API, potentially leading to unauthorized data access and manipulation. Proper application of security measures and regular monitoring of API interactions are essential to safeguard against such vulnerabilities.
Affected Version(s)
restapps < 16.0.41 < 16.0.41
restapps >= 17.0.0, < 17.0.6 < 17.0.0, 17.0.6
