Cross-Site Scripting Vulnerability in Frogman FreePBX Control
CVE-2026-46516
4.8MEDIUM
What is CVE-2026-46516?
Frogman, used for headless control of FreePBX, suffered from a security flaw where its chat-console's markdown formatter could insert regex capture groups as raw HTML. This vulnerability primarily affects versions prior to 1.6.6. Attackers could exploit user-controlled fields—such as extension names and IVR descriptions—to embed an HTML/JavaScript payload. When another admin viewed the compromised chat, the payload would execute in their session, taking on the viewer's permissions. While FreePBX’s admin GUI properly escapes these inputs, the chat formatter's inadequate handling exposes systems to potential security threats. The issue was rectified in version 1.6.6.
Affected Version(s)
frogman < 1.6.6
