Cross-Site Scripting Vulnerability in Frogman FreePBX Control
CVE-2026-46516

4.8MEDIUM

Key Information:

Vendor

Mwtcmi

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-46516?

Frogman, used for headless control of FreePBX, suffered from a security flaw where its chat-console's markdown formatter could insert regex capture groups as raw HTML. This vulnerability primarily affects versions prior to 1.6.6. Attackers could exploit user-controlled fields—such as extension names and IVR descriptions—to embed an HTML/JavaScript payload. When another admin viewed the compromised chat, the payload would execute in their session, taking on the viewer's permissions. While FreePBX’s admin GUI properly escapes these inputs, the chat formatter's inadequate handling exposes systems to potential security threats. The issue was rectified in version 1.6.6.

Affected Version(s)

frogman < 1.6.6

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.